2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10368 | — | — | 0.7% | Apr 25, 2018 | An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an ... |
| CVE-2018-10367 | — | — | 0.7% | Apr 25, 2018 | An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content secti... |
| CVE-2018-10366 | — | — | 2.6% | Apr 25, 2018 | An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam... |
| CVE-2018-10310 | — | — | 3.9% | Apr 25, 2018 | A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse... |
| CVE-2018-10362 | — | — | 1.5% | Apr 25, 2018 | An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in cla... |
| CVE-2018-10361 | — | — | 0.4% | Apr 25, 2018 | An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's ... |
| CVE-2018-3836 | HIGH | 7.8 | 1.5% | Apr 24, 2018 | An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially c... |
| CVE-2018-1059 | — | — | 0.9% | Apr 24, 2018 | The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contigu... |
| CVE-2018-4832 | HIGH | 7.5 | 2.5% | Apr 24, 2018 | A vulnerability has been identified in OpenPCS 7 V7.1 and earlier (All versions), OpenPCS 7 V8.0 (All versions), OpenPCS... |
| CVE-2018-9131 | — | — | — | Apr 24, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-9060 | — | — | — | Apr 24, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-7932 | — | — | 0.4% | Apr 24, 2018 | Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a ... |
| CVE-2018-7931 | — | — | 0.7% | Apr 24, 2018 | Huawei AppGallery versions before 8.0.4.301 has a whitelist mechanism bypass vulnerability. An attacker may set up a mal... |
| CVE-2018-5228 | — | — | 1.2% | Apr 24, 2018 | The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbit... |
| CVE-2018-7751 | — | — | 2.4% | Apr 24, 2018 | The svg_probe function in libavformat/img2dec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of ser... |
| CVE-2018-10329 | — | — | 0.8% | Apr 24, 2018 | app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter. |
| CVE-2018-10328 | — | — | 0.6% | Apr 24, 2018 | Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote at... |
| CVE-2018-10323 | — | — | 0.6% | Apr 24, 2018 | The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users... |
| CVE-2018-10322 | — | — | 0.5% | Apr 24, 2018 | The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to... |
| CVE-2018-10321 | — | — | 1.9% | Apr 24, 2018 | Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. |
| CVE-2018-10320 | — | — | 0.5% | Apr 24, 2018 | Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout. |
| CVE-2018-10319 | — | — | 0.6% | Apr 24, 2018 | Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet. |
| CVE-2018-10318 | — | — | 0.6% | Apr 24, 2018 | Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata. |
| CVE-2018-10316 | — | — | 1.1% | Apr 24, 2018 | Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a glob... |
| CVE-2018-10313 | — | — | 2.2% | Apr 24, 2018 | WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now