2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10289 | MEDIUM | 5.5 | 1.1% | Apr 22, 2018 | In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary ... |
| CVE-2018-10268 | — | — | 0.5% | Apr 22, 2018 | An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avat... |
| CVE-2018-10267 | — | — | 0.5% | Apr 22, 2018 | WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI. |
| CVE-2018-10266 | — | — | 0.6% | Apr 22, 2018 | BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&a... |
| CVE-2018-10265 | — | — | 0.5% | Apr 22, 2018 | An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the a... |
| CVE-2018-10126 | MEDIUM | 6.5 | 1.9% | Apr 21, 2018 | ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a cer... |
| CVE-2018-10284 | — | — | 1.1% | Apr 21, 2018 | Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter. |
| CVE-2018-10283 | — | — | 1.1% | Apr 21, 2018 | CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action. |
| CVE-2018-10254 | — | — | 1.4% | Apr 21, 2018 | Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Rem... |
| CVE-2018-10253 | — | — | 7.7% | Apr 21, 2018 | Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls. |
| CVE-2018-9059 | — | — | 77.3% | Apr 20, 2018 | Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code ... |
| CVE-2018-7747 | — | — | 4.6% | Apr 20, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re... |
| CVE-2018-10176 | — | — | 2.3% | Apr 20, 2018 | Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue. |
| CVE-2018-10175 | — | — | 1.2% | Apr 20, 2018 | Digital Guardian Management Console 7.1.2.0015 has an XXE issue. |
| CVE-2018-10174 | — | — | 1.2% | Apr 20, 2018 | Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files vi... |
| CVE-2018-10173 | — | — | 5.4% | Apr 20, 2018 | Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Uplo... |
| CVE-2018-10079 | HIGH | 7.8 | 0.8% | Apr 20, 2018 | Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users... |
| CVE-2018-10078 | MEDIUM | 4.8 | 2.1% | Apr 20, 2018 | Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i... |
| CVE-2018-10077 | MEDIUM | 4.9 | 8.3% | Apr 20, 2018 | XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re... |
| CVE-2018-8826 | — | — | 4.3% | Apr 20, 2018 | ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT... |
| CVE-2018-10249 | — | — | 0.5% | Apr 20, 2018 | baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account. |
| CVE-2018-1292 | — | — | 2.2% | Apr 20, 2018 | Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hack... |
| CVE-2018-1291 | — | — | 2.1% | Apr 20, 2018 | Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query d... |
| CVE-2018-1290 | — | — | 3.4% | Apr 20, 2018 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape... |
| CVE-2018-1289 | — | — | 2.7% | Apr 20, 2018 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different RE... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now