2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6796 | — | — | 0.6% | Feb 7, 2018 | PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field. |
| CVE-2018-6795 | — | — | 0.6% | Feb 7, 2018 | PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field. |
| CVE-2018-6655 | — | — | 0.6% | Feb 7, 2018 | PHP Scripts Mall Doctor Search Script 1.0.2 has Stored XSS via an arbitrary profile field. |
| CVE-2018-6574 | — | — | 7.7% | Feb 7, 2018 | Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command executi... |
| CVE-2018-6824 | — | — | 0.8% | Feb 7, 2018 | Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url paramete... |
| CVE-2018-1388 | — | — | 2.2% | Feb 7, 2018 | GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force I... |
| CVE-2018-1382 | — | — | 0.6% | Feb 7, 2018 | IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2018-1366 | — | — | 0.9% | Feb 7, 2018 | IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this... |
| CVE-2018-6823 | — | — | 1.5% | Feb 7, 2018 | In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implemen... |
| CVE-2018-6822 | — | — | 1.5% | Feb 7, 2018 | In PureVPN 6.0.1 on macOS, HelperTool LaunchDaemon implements an unprotected XPC service that can be abused to execute s... |
| CVE-2018-6806 | MEDIUM | 6.5 | 1.2% | Feb 7, 2018 | Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redi... |
| CVE-2018-6799 | — | — | 2.6% | Feb 7, 2018 | The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause ... |
| CVE-2018-6794 | — | — | 29.5% | Feb 7, 2018 | Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious se... |
| CVE-2018-6603 | — | — | 0.8% | Feb 7, 2018 | Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injecti... |
| CVE-2018-6792 | — | — | 1.1% | Feb 7, 2018 | Multiple SQL injection vulnerabilities in Saifor CVMS HUB 1.3.1 allow an authenticated user to execute arbitrary SQL com... |
| CVE-2018-6791 | — | — | 0.8% | Feb 7, 2018 | An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thum... |
| CVE-2018-6790 | — | — | 2.1% | Feb 7, 2018 | An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows ... |
| CVE-2018-6788 | — | — | 0.4% | Feb 6, 2018 | In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or p... |
| CVE-2018-6787 | — | — | 0.4% | Feb 6, 2018 | In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or p... |
| CVE-2018-6786 | — | — | 0.4% | Feb 6, 2018 | In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or p... |
| CVE-2018-6785 | — | — | 0.4% | Feb 6, 2018 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2018-6784 | — | — | 0.4% | Feb 6, 2018 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2018-6783 | — | — | 0.4% | Feb 6, 2018 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2018-6782 | — | — | 0.4% | Feb 6, 2018 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) ... |
| CVE-2018-6781 | — | — | 0.4% | Feb 6, 2018 | In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now