2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8969 | HIGH | 7.5 | 2.6% | Mar 24, 2018 | An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via direct... |
| CVE-2018-8968 | HIGH | 7.5 | 2.6% | Mar 24, 2018 | An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory tr... |
| CVE-2018-8967 | CRITICAL | 9.8 | 1.8% | Mar 24, 2018 | An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request. |
| CVE-2018-8966 | HIGH | 7.5 | 1.8% | Mar 24, 2018 | An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as de... |
| CVE-2018-8965 | HIGH | 7.5 | 2.6% | Mar 24, 2018 | An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory tr... |
| CVE-2018-8964 | — | — | 1.7% | Mar 23, 2018 | In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. Remote attackers could leverage this... |
| CVE-2018-8963 | — | — | 1.5% | Mar 23, 2018 | In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. Remote attackers could leverage... |
| CVE-2018-8962 | — | — | 1.7% | Mar 23, 2018 | In libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free. Remote attacke... |
| CVE-2018-8961 | — | — | 1.5% | Mar 23, 2018 | In libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free. Remote attackers could leverage t... |
| CVE-2018-8960 | — | — | 4.5% | Mar 23, 2018 | The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, le... |
| CVE-2018-8957 | — | — | 0.8% | Mar 23, 2018 | CoverCMS v1.1.6 has XSS via the fourth input box to index.php, related to admina/mconfigs.inc.php. |
| CVE-2018-1000141 | CRITICAL | 9.1 | 1.4% | Mar 23, 2018 | I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can r... |
| CVE-2018-1000140 | — | — | 9.7% | Mar 23, 2018 | rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates... |
| CVE-2018-1000139 | MEDIUM | 6.1 | 0.9% | Mar 23, 2018 | I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php... |
| CVE-2018-1000138 | CRITICAL | 9.1 | 1.6% | Mar 23, 2018 | I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php tha... |
| CVE-2018-1000137 | HIGH | 8.8 | 0.6% | Mar 23, 2018 | I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can re... |
| CVE-2018-1429 | MEDIUM | 5.4 | 1.1% | Mar 23, 2018 | IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2018-1000136 | — | — | 4.8% | Mar 23, 2018 | Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values ... |
| CVE-2018-8949 | — | — | 0.8% | Mar 23, 2018 | An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potenti... |
| CVE-2018-8948 | — | — | 0.8% | Mar 23, 2018 | In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module. |
| CVE-2018-7502 | — | — | 0.6% | Mar 23, 2018 | Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of use... |
| CVE-2018-1211 | — | — | 3.3% | Mar 23, 2018 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI par... |
| CVE-2018-1207 | — | — | 90.8% | Mar 23, 2018 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute... |
| CVE-2018-8945 | — | — | 2.1% | Mar 22, 2018 | The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in ... |
| CVE-2018-8944 | — | — | 1.2% | Mar 22, 2018 | PHPOK 4.8.338 has an arbitrary file upload vulnerability. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now