2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6903 | — | — | 1.1% | Apr 12, 2018 | PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail addres... |
| CVE-2018-6902 | — | — | 0.5% | Apr 12, 2018 | PHP Scripts Mall Image Sharing Script 1.3.3 has XSS via the Full Name field in an Edit Profile action. |
| CVE-2018-6900 | — | — | 0.5% | Apr 12, 2018 | PHP Scripts Mall Website Broker Script 3.0.6 has XSS via the Last Name field on the My Profile page. |
| CVE-2018-6879 | — | — | 1.1% | Apr 12, 2018 | PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allo... |
| CVE-2018-6870 | — | — | 0.7% | Apr 12, 2018 | Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature. |
| CVE-2018-5254 | — | — | 1.3% | Apr 12, 2018 | Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path ... |
| CVE-2018-3889 | HIGH | 7.8 | 1.5% | Apr 12, 2018 | A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary da... |
| CVE-2018-3868 | HIGH | 7.8 | 1.3% | Apr 12, 2018 | A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary d... |
| CVE-2018-3862 | HIGH | 7.8 | 1.0% | Apr 12, 2018 | A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting |
| CVE-2018-3861 | HIGH | 7.8 | 1.5% | Apr 12, 2018 | A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary d... |
| CVE-2018-10063 | — | — | 9.6% | Apr 12, 2018 | The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that ... |
| CVE-2018-10074 | — | — | 0.3% | Apr 12, 2018 | The hi3660_stub_clk_probe function in drivers/clk/hisilicon/clk-hi3660-stub.c in the Linux kernel before 4.16 allows loc... |
| CVE-2018-10073 | — | — | 0.6% | Apr 12, 2018 | joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter. |
| CVE-2018-10072 | — | — | 0.4% | Apr 12, 2018 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x9538... |
| CVE-2018-10071 | — | — | 0.4% | Apr 12, 2018 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x9538... |
| CVE-2018-10068 | — | — | 4.1% | Apr 12, 2018 | The jDownloads extension before 3.2.59 for Joomla! has XSS. |
| CVE-2018-1084 | HIGH | 7.5 | 3.2% | Apr 12, 2018 | corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. |
| CVE-2018-1079 | HIGH | 8.7 | 1.1% | Apr 12, 2018 | pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The... |
| CVE-2018-1086 | MEDIUM | 4.3 | 1.7% | Apr 12, 2018 | pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd servi... |
| CVE-2018-10061 | MEDIUM | 5.4 | 1.1% | Apr 12, 2018 | Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occ... |
| CVE-2018-10060 | MEDIUM | 5.4 | 1.0% | Apr 12, 2018 | Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_ur... |
| CVE-2018-10059 | — | — | 1.2% | Apr 12, 2018 | Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] in... |
| CVE-2018-9843 | — | — | 17.3% | Apr 12, 2018 | The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute ... |
| CVE-2018-9842 | — | — | 14.1% | Apr 12, 2018 | CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay... |
| CVE-2018-9155 | — | — | 1.2% | Apr 12, 2018 | Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now