2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0520 | — | — | 0.7% | Feb 23, 2018 | Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hi... |
| CVE-2018-0519 | — | — | 0.6% | Feb 23, 2018 | Cross-site scripting vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to inject arbitrar... |
| CVE-2018-0518 | — | — | 0.6% | Feb 23, 2018 | LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle ... |
| CVE-2018-7339 | — | — | 1.4% | Feb 23, 2018 | The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, w... |
| CVE-2018-6868 | — | — | 0.6% | Feb 23, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Prof... |
| CVE-2018-6867 | — | — | 0.7% | Feb 23, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter. |
| CVE-2018-6866 | — | — | 1.6% | Feb 23, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a craf... |
| CVE-2018-6489 | — | — | 1.3% | Feb 22, 2018 | XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulne... |
| CVE-2018-6488 | HIGH | 8.1 | 1.8% | Feb 22, 2018 | Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could... |
| CVE-2018-0015 | CRITICAL | 9.8 | 1.1% | Feb 22, 2018 | A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Pytho... |
| CVE-2018-7319 | — | — | 2.1% | Feb 22, 2018 | SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system... |
| CVE-2018-7318 | CRITICAL | 9.8 | 9.0% | Feb 22, 2018 | SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, descrip... |
| CVE-2018-7317 | — | — | 8.4% | Feb 22, 2018 | Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/. |
| CVE-2018-7316 | — | — | 8.5% | Feb 22, 2018 | Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. |
| CVE-2018-7315 | — | — | 2.8% | Feb 22, 2018 | SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, cast... |
| CVE-2018-7314 | — | — | 59.6% | Feb 22, 2018 | SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerabil... |
| CVE-2018-7312 | — | — | 2.8% | Feb 22, 2018 | SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter. |
| CVE-2018-7301 | — | — | 1.5% | Feb 22, 2018 | eQ-3 AG HomeMatic CCU2 2.29.22 devices have an open XML-RPC port without authentication. This can be exploited by sendin... |
| CVE-2018-7300 | CRITICAL | 9.8 | 31.8% | Feb 22, 2018 | Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic C... |
| CVE-2018-7299 | — | — | 1.2% | Feb 22, 2018 | Remote Code Execution in the addon installation process in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows authenticate... |
| CVE-2018-7298 | — | — | 0.8% | Feb 22, 2018 | In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are do... |
| CVE-2018-7297 | — | — | 65.3% | Feb 22, 2018 | Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers... |
| CVE-2018-7296 | — | — | 1.9% | Feb 22, 2018 | Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows... |
| CVE-2018-6890 | — | — | 0.7% | Feb 22, 2018 | Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/p... |
| CVE-2018-1417 | HIGH | 8.1 | 2.2% | Feb 22, 2018 | Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code r... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now