2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-8969HIGH7.5An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via direct...
CVE-2018-8968HIGH7.5An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory tr...
CVE-2018-8967CRITICAL9.8An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
CVE-2018-8966HIGH7.5An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as de...
CVE-2018-8965HIGH7.5An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory tr...
CVE-2018-8964In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. Remote attackers could leverage this...
CVE-2018-8963In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. Remote attackers could leverage...
CVE-2018-8962In libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free. Remote attacke...
CVE-2018-8961In libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free. Remote attackers could leverage t...
CVE-2018-8960The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, le...
CVE-2018-8957CoverCMS v1.1.6 has XSS via the fourth input box to index.php, related to admina/mconfigs.inc.php.
CVE-2018-1000141CRITICAL9.1I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can r...
CVE-2018-1000140rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates...
CVE-2018-1000139MEDIUM6.1I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php...
CVE-2018-1000138CRITICAL9.1I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php tha...
CVE-2018-1000137HIGH8.8I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can re...
CVE-2018-1429MEDIUM5.4IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2018-1000136Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values ...
CVE-2018-8949An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potenti...
CVE-2018-8948In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
CVE-2018-7502Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of use...
CVE-2018-1211Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI par...
CVE-2018-1207Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute...
CVE-2018-8945The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in ...
CVE-2018-8944PHPOK 4.8.338 has an arbitrary file upload vulnerability.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now