2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-6378In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the m...
CVE-2018-11369An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the databas...
CVE-2018-11328An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI contain...
CVE-2018-11327An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were...
CVE-2018-11326An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities...
CVE-2018-11325An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after e...
CVE-2018-11324An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core ...
CVE-2018-11323An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of use...
CVE-2018-11322An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled...
CVE-2018-11321An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to crea...
CVE-2018-6963VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabiliti...
CVE-2018-6962VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalat...
CVE-2018-1583IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-c...
CVE-2018-11367An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module.
CVE-2018-11366init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS)...
CVE-2018-3640Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may ...
CVE-2018-3639MEDIUM5.5Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres...
CVE-2018-11329HIGH7.5The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attackers to take ...
CVE-2018-11365sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop.
CVE-2018-11364sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak r...
CVE-2018-11363jpeg_size in pdfgen.c in PDFGen before 2018-04-09 has a heap-based buffer over-read.
CVE-2018-11346An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability t...
CVE-2018-11345An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload sup...
CVE-2018-11344A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify...
CVE-2018-11343A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attac...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now