2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0487 | — | — | 3.3% | Feb 13, 2018 | ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a... |
| CVE-2018-6911 | — | — | 13.0% | Feb 13, 2018 | The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS... |
| CVE-2018-6293 | — | — | 1.2% | Feb 13, 2018 | Arbitrary File Read in Saperion Web Client version 7.5.2 83166. |
| CVE-2018-6292 | — | — | 3.8% | Feb 13, 2018 | Remote Code Execution in Saperion Web Client version 7.5.2 83166. |
| CVE-2018-1297 | — | — | 10.1% | Feb 13, 2018 | When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could all... |
| CVE-2018-6942 | — | — | 2.1% | Feb 13, 2018 | An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ... |
| CVE-2018-6930 | — | — | 2.2% | Feb 13, 2018 | A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0... |
| CVE-2018-1214 | — | — | 0.8% | Feb 12, 2018 | Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default... |
| CVE-2018-6927 | — | — | 0.7% | Feb 12, 2018 | The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial ... |
| CVE-2018-6926 | — | — | 1.7% | Feb 12, 2018 | In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on ce... |
| CVE-2018-6893 | — | — | 2.5% | Feb 12, 2018 | controllers/member/Api.php in dayrui FineCms 5.2.0 has SQL Injection: a request with s=member,c=api,m=checktitle, and th... |
| CVE-2018-6506 | — | — | 0.5% | Feb 12, 2018 | Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use o... |
| CVE-2018-6889 | — | — | 6.8% | Feb 12, 2018 | An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a m... |
| CVE-2018-6888 | — | — | 2.0% | Feb 12, 2018 | An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cro... |
| CVE-2018-6881 | MEDIUM | 5.3 | 2.2% | Feb 12, 2018 | EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic... |
| CVE-2018-6880 | MEDIUM | 5.3 | 1.8% | Feb 12, 2018 | EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/... |
| CVE-2018-6864 | — | — | 0.6% | Feb 12, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile upd... |
| CVE-2018-6863 | — | — | 1.5% | Feb 12, 2018 | SQL Injection exists in PHP Scripts Mall Select Your College Script 2.0.2 via a Login Parameter. |
| CVE-2018-6862 | — | — | 0.7% | Feb 12, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Bitcoin MLM Software 1.0.2 via a profile field. |
| CVE-2018-6861 | MEDIUM | 5.4 | 0.6% | Feb 12, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter. |
| CVE-2018-6860 | HIGH | 8.8 | 2.5% | Feb 12, 2018 | Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a pr... |
| CVE-2018-6858 | MEDIUM | 5.4 | 0.6% | Feb 12, 2018 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script. |
| CVE-2018-6845 | MEDIUM | 6.1 | 2.5% | Feb 12, 2018 | PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field. |
| CVE-2018-6912 | — | — | 1.5% | Feb 12, 2018 | The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial o... |
| CVE-2018-6892 | — | — | 93.6% | Feb 11, 2018 | An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now