2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7724 | — | — | 0.3% | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} re... |
| CVE-2018-7723 | — | — | 0.6% | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request... |
| CVE-2018-7722 | — | — | 0.6% | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploi... |
| CVE-2018-1000101 | — | — | 2.4% | Mar 6, 2018 | Mingw-w64 version 5.0.3 and earlier, 5.0.4, 6.0.0 and 7.0.0 contains an Improper Null Termination (CWE-170) vulnerabilit... |
| CVE-2018-1000100 | — | — | 1.1% | Mar 6, 2018 | GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2... |
| CVE-2018-7650 | — | — | 0.5% | Mar 6, 2018 | PHP Scripts Mall Hot Scripts Clone:Script Classified Version 3.1 Application is vulnerable to stored XSS within the "Add... |
| CVE-2018-7307 | — | — | 0.5% | Mar 6, 2018 | The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the... |
| CVE-2018-1062 | MEDIUM | 5.3 | 1.4% | Mar 6, 2018 | A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delet... |
| CVE-2018-7717 | — | — | 0.7% | Mar 5, 2018 | The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.... |
| CVE-2018-7716 | — | — | 2.4% | Mar 5, 2018 | PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability with its com.privat.vpn.helper privil... |
| CVE-2018-7715 | — | — | 2.4% | Mar 5, 2018 | PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability with its com.privat.vpn.helper privil... |
| CVE-2018-7714 | — | — | 2.3% | Mar 5, 2018 | The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cau... |
| CVE-2018-7713 | — | — | 2.4% | Mar 5, 2018 | The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cau... |
| CVE-2018-7712 | HIGH | 7.5 | 2.3% | Mar 5, 2018 | The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cau... |
| CVE-2018-7711 | — | — | 1.2% | Mar 5, 2018 | HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the sign... |
| CVE-2018-7493 | — | — | 1.9% | Mar 5, 2018 | CactusVPN through 6.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. Th... |
| CVE-2018-7698 | — | — | 1.1% | Mar 5, 2018 | An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlin... |
| CVE-2018-5255 | — | — | 1.1% | Mar 5, 2018 | The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of se... |
| CVE-2018-5455 | — | — | 1.6% | Mar 5, 2018 | A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series ve... |
| CVE-2018-5453 | — | — | 1.2% | Mar 5, 2018 | An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4... |
| CVE-2018-5449 | — | — | 0.5% | Mar 5, 2018 | A NULL Pointer Dereference issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. T... |
| CVE-2018-0491 | — | — | 15.6% | Mar 5, 2018 | A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of se... |
| CVE-2018-0490 | — | — | 2.7% | Mar 5, 2018 | An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-auth... |
| CVE-2018-7644 | — | — | 1.3% | Mar 5, 2018 | The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SA... |
| CVE-2018-1316 | — | — | 3.2% | Mar 5, 2018 | The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now