2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-7557MEDIUM6.5The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denia...
CVE-2018-7547MEDIUM4.8lyadmin 1.x has XSS via the config[WEB_SITE_TITLE] parameter to the /admin.php?s=/admin/config/groupsave.html URI.
CVE-2018-7479MEDIUM5.3YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.ph...
CVE-2018-7434MEDIUM5.3zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase....
CVE-2018-7274MEDIUM6.1Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Questio...
CVE-2018-6356MEDIUM6.5Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base...
CVE-2018-5381MEDIUM6.5The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in ...
CVE-2018-5380MEDIUM4.3The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for d...
CVE-2018-1049MEDIUM5.9In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from ke...
CVE-2018-1000068MEDIUM5.3An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, tha...
CVE-2018-1000067MEDIUM5.3An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that a...
CVE-2018-6881MEDIUM5.3EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic...
CVE-2018-6880MEDIUM5.3EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/...
CVE-2018-6861MEDIUM5.4Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter.
CVE-2018-6858MEDIUM5.4Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script.
CVE-2018-6845MEDIUM6.1PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.
CVE-2018-6891MEDIUM6.1Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
CVE-2018-1000021MEDIUM5GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems inc...
CVE-2018-0140MEDIUM6.5A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance...
CVE-2018-0138MEDIUM5.3A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack...
CVE-2018-0134MEDIUM5.3A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke...
CVE-2018-0122MEDIUM4.4A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c...
CVE-2018-6806MEDIUM6.5Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redi...
CVE-2018-6621MEDIUM6.5The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of ...
CVE-2018-6616MEDIUM5.5In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers co...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now