2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9864 | — | — | 1.4% | Apr 9, 2018 | The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field. |
| CVE-2018-9862 | — | — | 0.4% | Apr 9, 2018 | util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveragin... |
| CVE-2018-1308 | — | — | 20.9% | Apr 9, 2018 | This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in t... |
| CVE-2018-0556 | — | — | 0.7% | Apr 9, 2018 | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. |
| CVE-2018-0555 | — | — | 1.6% | Apr 9, 2018 | Buffer overflow in Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary code via a speciall... |
| CVE-2018-0554 | — | — | 0.8% | Apr 9, 2018 | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on ... |
| CVE-2018-0553 | — | — | 0.5% | Apr 9, 2018 | The iRemoconWiFi App for Android version 4.1.7 and earlier does not verify X.509 certificates from SSL servers, which al... |
| CVE-2018-0545 | — | — | 3.1% | Apr 9, 2018 | LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
| CVE-2018-9857 | — | — | 2.3% | Apr 9, 2018 | PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc... |
| CVE-2018-9856 | — | — | 0.7% | Apr 9, 2018 | Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a pe... |
| CVE-2018-6905 | — | — | 2.3% | Apr 8, 2018 | The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demons... |
| CVE-2018-9852 | CRITICAL | 9.8 | 1.4% | Apr 8, 2018 | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by... |
| CVE-2018-9851 | — | — | 1.8% | Apr 8, 2018 | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified... |
| CVE-2018-9850 | — | — | 1.9% | Apr 8, 2018 | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directo... |
| CVE-2018-9848 | — | — | 2.2% | Apr 7, 2018 | In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to ex... |
| CVE-2018-9847 | — | — | 1.6% | Apr 7, 2018 | In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execu... |
| CVE-2018-9846 | — | — | 2.3% | Apr 7, 2018 | In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the ... |
| CVE-2018-9327 | — | — | 1.6% | Apr 7, 2018 | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be... |
| CVE-2018-9326 | — | — | 2.0% | Apr 7, 2018 | Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code. |
| CVE-2018-9325 | — | — | 1.2% | Apr 7, 2018 | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledg... |
| CVE-2018-9330 | — | — | 0.5% | Apr 7, 2018 | register.jsp in Coremail XT3.0 allows stored XSS, as demonstrated by the third form field to a URI under register/, a di... |
| CVE-2018-9844 | — | — | 3.8% | Apr 7, 2018 | The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS. |
| CVE-2018-9841 | — | — | 1.8% | Apr 7, 2018 | The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of s... |
| CVE-2018-1000157 | — | — | — | Apr 7, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9092. Reason: This candidate is a reservation ... |
| CVE-2018-9331 | HIGH | 7.5 | 2.6% | Apr 7, 2018 | An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory trave... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now