2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-7479MEDIUM5.3YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.ph...
CVE-2018-7434MEDIUM5.3zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase....
CVE-2018-7274MEDIUM6.1Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Questio...
CVE-2018-6356MEDIUM6.5Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base...
CVE-2018-5381MEDIUM6.5The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in ...
CVE-2018-5380MEDIUM4.3The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for d...
CVE-2018-1049MEDIUM5.9In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from ke...
CVE-2018-1000068MEDIUM5.3An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, tha...
CVE-2018-1000067MEDIUM5.3An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that a...
CVE-2018-6881MEDIUM5.3EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic...
CVE-2018-6880MEDIUM5.3EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/...
CVE-2018-6861MEDIUM5.4Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter.
CVE-2018-6858MEDIUM5.4Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script.
CVE-2018-6845MEDIUM6.1PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.
CVE-2018-6891MEDIUM6.1Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
CVE-2018-1000021MEDIUM5GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems inc...
CVE-2018-0140MEDIUM6.5A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance...
CVE-2018-0138MEDIUM5.3A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack...
CVE-2018-0134MEDIUM5.3A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke...
CVE-2018-0122MEDIUM4.4A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c...
CVE-2018-6806MEDIUM6.5Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redi...
CVE-2018-6621MEDIUM6.5The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of ...
CVE-2018-6616MEDIUM5.5In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers co...
CVE-2018-6612MEDIUM5.5An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-r...
CVE-2018-1185MEDIUM6.7An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now