2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-6903PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail addres...
CVE-2018-6902PHP Scripts Mall Image Sharing Script 1.3.3 has XSS via the Full Name field in an Edit Profile action.
CVE-2018-6900PHP Scripts Mall Website Broker Script 3.0.6 has XSS via the Last Name field on the My Profile page.
CVE-2018-6879PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allo...
CVE-2018-6870Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature.
CVE-2018-5254Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path ...
CVE-2018-3889HIGH7.8A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary da...
CVE-2018-3868HIGH7.8A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary d...
CVE-2018-3862HIGH7.8A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting
CVE-2018-3861HIGH7.8A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary d...
CVE-2018-10063The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that ...
CVE-2018-10074The hi3660_stub_clk_probe function in drivers/clk/hisilicon/clk-hi3660-stub.c in the Linux kernel before 4.16 allows loc...
CVE-2018-10073joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter.
CVE-2018-10072windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x9538...
CVE-2018-10071windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x9538...
CVE-2018-10068The jDownloads extension before 3.2.59 for Joomla! has XSS.
CVE-2018-1084HIGH7.5corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
CVE-2018-1079HIGH8.7pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The...
CVE-2018-1086MEDIUM4.3pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd servi...
CVE-2018-10061MEDIUM5.4Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occ...
CVE-2018-10060MEDIUM5.4Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_ur...
CVE-2018-10059Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] in...
CVE-2018-9843The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute ...
CVE-2018-9842CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay...
CVE-2018-9155Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now