2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5230 | — | — | 37.6% | May 14, 2018 | The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 ... |
| CVE-2018-0591 | — | — | 0.9% | May 14, 2018 | The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates f... |
| CVE-2018-0590 | — | — | 1.1% | May 14, 2018 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr... |
| CVE-2018-0589 | — | — | 1.1% | May 14, 2018 | Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restr... |
| CVE-2018-0588 | — | — | 2.6% | May 14, 2018 | Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress al... |
| CVE-2018-0587 | — | — | 1.1% | May 14, 2018 | Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote auth... |
| CVE-2018-0586 | — | — | 1.6% | May 14, 2018 | Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPr... |
| CVE-2018-0585 | — | — | 1.0% | May 14, 2018 | Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attacker... |
| CVE-2018-0583 | — | — | 0.9% | May 14, 2018 | Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attacker... |
| CVE-2018-0582 | — | — | 0.9% | May 14, 2018 | Cross-site scripting vulnerability in ASUS RT-AC68U Firmware version prior to 3.0.0.4.380.1031 allows remote attackers t... |
| CVE-2018-0581 | — | — | 0.9% | May 14, 2018 | Cross-site scripting vulnerability in ASUS RT-AC87U Firmware version prior to 3.0.0.4.378.9383 allows remote attackers t... |
| CVE-2018-0580 | — | — | 2.1% | May 14, 2018 | Untrusted search path vulnerability in CELSYS, Inc CLIP STUDIO series (CLIP STUDIO PAINT (for Windows) EX/PRO/DEBUT Ver.... |
| CVE-2018-0579 | — | — | 1.1% | May 14, 2018 | Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2... |
| CVE-2018-0578 | — | — | 0.8% | May 14, 2018 | Cross-site scripting vulnerability in PixelYourSite plugin prior to version 5.3.0 for WordPress allows remote attackers ... |
| CVE-2018-0577 | MEDIUM | 5.4 | 1.1% | May 14, 2018 | Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers ... |
| CVE-2018-0576 | — | — | 1.5% | May 14, 2018 | Cross-site scripting vulnerability in Events Manager plugin prior to version 5.9 for WordPress allows remote attackers t... |
| CVE-2018-0568 | — | — | 1.7% | May 14, 2018 | Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated us... |
| CVE-2018-11037 | — | — | 2.4% | May 14, 2018 | In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an informat... |
| CVE-2018-11035 | — | — | 0.4% | May 14, 2018 | In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser... |
| CVE-2018-11034 | — | — | 1.0% | May 14, 2018 | In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser... |
| CVE-2018-10944 | — | — | 1.0% | May 14, 2018 | The request_dividend function of a smart contract implementation for ROC (aka Rasputin Online Coin), an Ethereum ERC20 t... |
| CVE-2018-11033 | — | — | 1.3% | May 14, 2018 | The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause... |
| CVE-2018-11032 | — | — | 1.5% | May 14, 2018 | PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function. |
| CVE-2018-11031 | — | — | 2.0% | May 14, 2018 | application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an a... |
| CVE-2018-11018 | — | — | 0.6% | May 13, 2018 | An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/sys... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now