2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1283 | — | — | 10.1% | Mar 26, 2018 | In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (Session... |
| CVE-2018-5474 | — | — | 6.2% | Mar 26, 2018 | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remot... |
| CVE-2018-5472 | — | — | 4.7% | Mar 26, 2018 | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could a... |
| CVE-2018-5470 | — | — | 0.6% | Mar 26, 2018 | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that ... |
| CVE-2018-5468 | — | — | 4.7% | Mar 26, 2018 | Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an ... |
| CVE-2018-5466 | — | — | 2.0% | Mar 26, 2018 | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could... |
| CVE-2018-5464 | — | — | 2.0% | Mar 26, 2018 | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could ... |
| CVE-2018-5462 | — | — | 2.0% | Mar 26, 2018 | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability th... |
| CVE-2018-5458 | — | — | 1.3% | Mar 26, 2018 | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could... |
| CVE-2018-5454 | — | — | 3.5% | Mar 26, 2018 | Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability where code debugging methods are enabl... |
| CVE-2018-9020 | — | — | 1.1% | Mar 26, 2018 | The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Go... |
| CVE-2018-9018 | — | — | 3.2% | Mar 25, 2018 | In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could... |
| CVE-2018-8979 | — | — | 1.3% | Mar 25, 2018 | Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the cre... |
| CVE-2018-8978 | — | — | 0.5% | Mar 25, 2018 | Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI. |
| CVE-2018-8817 | — | — | 3.3% | Mar 25, 2018 | Wampserver before 3.1.3 has CSRF in add_vhost.php. |
| CVE-2018-9017 | — | — | 0.6% | Mar 25, 2018 | dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI. |
| CVE-2018-9016 | — | — | 0.7% | Mar 25, 2018 | dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI. |
| CVE-2018-9015 | — | — | 0.6% | Mar 25, 2018 | dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box... |
| CVE-2018-9014 | — | — | 1.2% | Mar 25, 2018 | dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request. |
| CVE-2018-9010 | HIGH | 7.2 | 9.8% | Mar 25, 2018 | Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via t... |
| CVE-2018-8947 | — | — | 11.6% | Mar 25, 2018 | rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easi... |
| CVE-2018-7719 | — | — | 46.3% | Mar 25, 2018 | Acrolinx Server before 5.2.5 on Windows allows Directory Traversal. |
| CVE-2018-9009 | — | — | 1.9% | Mar 25, 2018 | In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file. |
| CVE-2018-9007 | — | — | 0.4% | Mar 25, 2018 | In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of ser... |
| CVE-2018-9006 | — | — | 0.4% | Mar 25, 2018 | In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial o... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now