2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1083 | — | — | 0.6% | Mar 28, 2018 | Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unpr... |
| CVE-2018-9109 | CRITICAL | 9.1 | 3.0% | Mar 28, 2018 | Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function... |
| CVE-2018-9108 | — | — | 0.8% | Mar 28, 2018 | CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account w... |
| CVE-2018-9107 | — | — | 7.4% | Mar 28, 2018 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing exte... |
| CVE-2018-9106 | — | — | 5.6% | Mar 28, 2018 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio... |
| CVE-2018-8823 | — | — | 51.6% | Mar 28, 2018 | modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for Pre... |
| CVE-2018-9105 | — | — | 2.7% | Mar 27, 2018 | NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privil... |
| CVE-2018-9092 | — | — | 2.5% | Mar 27, 2018 | There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password. |
| CVE-2018-9058 | — | — | 1.2% | Mar 27, 2018 | In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers c... |
| CVE-2018-1327 | — | — | 9.2% | Mar 27, 2018 | The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a m... |
| CVE-2018-1238 | — | — | 1.5% | Mar 27, 2018 | Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA).... |
| CVE-2018-1237 | — | — | 1.6% | Mar 27, 2018 | Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light i... |
| CVE-2018-1205 | — | — | 1.5% | Mar 27, 2018 | Dell EMC ScaleIO, versions prior to 2.5, do not properly handle some packet data in the MDM service. As a result, a remo... |
| CVE-2018-1091 | — | — | 0.4% | Mar 27, 2018 | In the flush_tmregs_to_thread function in arch/powerpc/kernel/ptrace.c in the Linux kernel before 4.13.5, a guest kernel... |
| CVE-2018-0739 | — | — | 19.3% | Mar 27, 2018 | Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack gi... |
| CVE-2018-0733 | — | — | 8.6% | Mar 27, 2018 | Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least s... |
| CVE-2018-9057 | — | — | 2.0% | Mar 27, 2018 | aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0... |
| CVE-2018-7700 | — | — | 71.7% | Mar 27, 2018 | DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php... |
| CVE-2018-9056 | — | — | 0.7% | Mar 27, 2018 | Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an atta... |
| CVE-2018-8048 | — | — | 2.0% | Mar 27, 2018 | In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing ... |
| CVE-2018-7196 | MEDIUM | 6.1 | 2.5% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers... |
| CVE-2018-7195 | HIGH | 8.1 | 1.0% | Mar 27, 2018 | Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail addre... |
| CVE-2018-7194 | MEDIUM | 4.9 | 1.3% | Mar 27, 2018 | Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attacker... |
| CVE-2018-7193 | MEDIUM | 6.1 | 2.5% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attac... |
| CVE-2018-7192 | MEDIUM | 6.1 | 2.1% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remot... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now