2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7479 | MEDIUM | 5.3 | 2.1% | Feb 26, 2018 | YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.ph... |
| CVE-2018-7434 | MEDIUM | 5.3 | 2.3% | Feb 24, 2018 | zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.... |
| CVE-2018-7274 | MEDIUM | 6.1 | 1.0% | Feb 21, 2018 | Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Questio... |
| CVE-2018-6356 | MEDIUM | 6.5 | 3.9% | Feb 20, 2018 | Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base... |
| CVE-2018-5381 | MEDIUM | 6.5 | 30.5% | Feb 19, 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in ... |
| CVE-2018-5380 | MEDIUM | 4.3 | 15.0% | Feb 19, 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can overrun internal BGP code-to-string conversion tables used for d... |
| CVE-2018-1049 | MEDIUM | 5.9 | 7.3% | Feb 16, 2018 | In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from ke... |
| CVE-2018-1000068 | MEDIUM | 5.3 | 2.0% | Feb 16, 2018 | An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, tha... |
| CVE-2018-1000067 | MEDIUM | 5.3 | 1.7% | Feb 16, 2018 | An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that a... |
| CVE-2018-6881 | MEDIUM | 5.3 | 2.2% | Feb 12, 2018 | EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic... |
| CVE-2018-6880 | MEDIUM | 5.3 | 1.8% | Feb 12, 2018 | EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/... |
| CVE-2018-6861 | MEDIUM | 5.4 | 0.6% | Feb 12, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter. |
| CVE-2018-6858 | MEDIUM | 5.4 | 0.6% | Feb 12, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script. |
| CVE-2018-6845 | MEDIUM | 6.1 | 2.5% | Feb 12, 2018 | PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field. |
| CVE-2018-6891 | MEDIUM | 6.1 | 1.0% | Feb 11, 2018 | Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js. |
| CVE-2018-1000021 | MEDIUM | 5 | 1.1% | Feb 9, 2018 | GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems inc... |
| CVE-2018-0140 | MEDIUM | 6.5 | 1.6% | Feb 8, 2018 | A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance... |
| CVE-2018-0138 | MEDIUM | 5.3 | 1.2% | Feb 8, 2018 | A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack... |
| CVE-2018-0134 | MEDIUM | 5.3 | 1.4% | Feb 8, 2018 | A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacke... |
| CVE-2018-0122 | MEDIUM | 4.4 | 0.4% | Feb 8, 2018 | A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c... |
| CVE-2018-6806 | MEDIUM | 6.5 | 1.2% | Feb 7, 2018 | Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redi... |
| CVE-2018-6621 | MEDIUM | 6.5 | 2.2% | Feb 5, 2018 | The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of ... |
| CVE-2018-6616 | MEDIUM | 5.5 | 1.7% | Feb 4, 2018 | In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers co... |
| CVE-2018-6612 | MEDIUM | 5.5 | 1.1% | Feb 4, 2018 | An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-r... |
| CVE-2018-1185 | MEDIUM | 6.7 | 6.3% | Feb 3, 2018 | An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now