2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10312 | — | — | 2.5% | Apr 24, 2018 | index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member. |
| CVE-2018-10311 | — | — | 2.6% | Apr 24, 2018 | A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitr... |
| CVE-2018-10309 | — | — | 2.9% | Apr 24, 2018 | The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS. |
| CVE-2018-10305 | — | — | 1.2% | Apr 24, 2018 | The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use th... |
| CVE-2018-6491 | HIGH | 8.1 | 1.0% | Apr 24, 2018 | Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 1... |
| CVE-2018-10303 | — | — | 2.6% | Apr 23, 2018 | A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code,... |
| CVE-2018-1106 | — | — | 0.4% | Apr 23, 2018 | An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privile... |
| CVE-2018-8781 | HIGH | 7.8 | 0.5% | Apr 23, 2018 | The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 ha... |
| CVE-2018-10302 | — | — | 3.2% | Apr 23, 2018 | A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code,... |
| CVE-2018-9921 | — | — | 1.5% | Apr 23, 2018 | In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and director... |
| CVE-2018-8880 | — | — | 14.6% | Apr 23, 2018 | Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th... |
| CVE-2018-10301 | — | — | 1.0% | Apr 23, 2018 | Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress a... |
| CVE-2018-10300 | — | — | 1.0% | Apr 23, 2018 | Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows re... |
| CVE-2018-4847 | — | — | 0.3% | Apr 23, 2018 | A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection ... |
| CVE-2018-3850 | HIGH | 8.8 | 2.9% | Apr 23, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine Foxit Software Foxit PDF Reader version 9.0.... |
| CVE-2018-10234 | — | — | 0.6% | Apr 23, 2018 | Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "A... |
| CVE-2018-10233 | — | — | 0.7% | Apr 23, 2018 | The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site reques... |
| CVE-2018-10299 | — | — | 2.8% | Apr 23, 2018 | An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), th... |
| CVE-2018-10298 | — | — | 0.5% | Apr 22, 2018 | Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_porta... |
| CVE-2018-10297 | — | — | 0.5% | Apr 22, 2018 | Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IM... |
| CVE-2018-10296 | — | — | 0.8% | Apr 22, 2018 | MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter. |
| CVE-2018-10295 | — | — | 0.5% | Apr 22, 2018 | ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account. |
| CVE-2018-9245 | — | — | 4.2% | Apr 22, 2018 | The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that a... |
| CVE-2018-10286 | — | — | 6.7% | Apr 22, 2018 | The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th... |
| CVE-2018-10285 | — | — | 13.7% | Apr 22, 2018 | The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now