2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6656 | — | — | 0.5% | Feb 6, 2018 | Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories. |
| CVE-2018-6469 | — | — | 0.9% | Feb 6, 2018 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at... |
| CVE-2018-6468 | — | — | 0.9% | Feb 6, 2018 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at... |
| CVE-2018-6467 | — | — | 0.6% | Feb 6, 2018 | The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php. |
| CVE-2018-6466 | — | — | 0.9% | Feb 6, 2018 | A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote at... |
| CVE-2018-6654 | — | — | 0.5% | Feb 6, 2018 | The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'a... |
| CVE-2018-6569 | — | — | 1.5% | Feb 6, 2018 | West Wind Web Server 6.x does not require authentication for /ADMIN.ASP. |
| CVE-2018-6651 | — | — | 2.2% | Feb 5, 2018 | In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin ... |
| CVE-2018-6610 | — | — | 8.1% | Feb 5, 2018 | Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request. |
| CVE-2018-6609 | — | — | 2.7% | Feb 5, 2018 | SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit acti... |
| CVE-2018-6605 | — | — | 58.3% | Feb 5, 2018 | SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get... |
| CVE-2018-6604 | — | — | 2.7% | Feb 5, 2018 | SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail... |
| CVE-2018-6582 | — | — | 2.8% | Feb 5, 2018 | SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge... |
| CVE-2018-6635 | — | — | 1.2% | Feb 5, 2018 | System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows rem... |
| CVE-2018-6633 | — | — | 0.4% | Feb 5, 2018 | In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a de... |
| CVE-2018-6632 | — | — | 0.4% | Feb 5, 2018 | In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a de... |
| CVE-2018-6631 | — | — | 0.4% | Feb 5, 2018 | In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110009.sys) allows local users to cause a de... |
| CVE-2018-6630 | — | — | 0.4% | Feb 5, 2018 | In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a de... |
| CVE-2018-6629 | — | — | 0.4% | Feb 5, 2018 | In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a de... |
| CVE-2018-6628 | — | — | 0.4% | Feb 5, 2018 | In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a de... |
| CVE-2018-6627 | — | — | 0.4% | Feb 5, 2018 | In WatchDog Anti-Malware 2.74.186.150, the driver file (ZAMGUARD32.SYS) allows local users to cause a denial of service ... |
| CVE-2018-6626 | — | — | 0.4% | Feb 5, 2018 | In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a de... |
| CVE-2018-6625 | — | — | 0.4% | Feb 5, 2018 | In WatchDog Anti-Malware 2.74.186.150, the driver file (ZAMGUARD32.SYS) allows local users to cause a denial of service ... |
| CVE-2018-6624 | — | — | 1.7% | Feb 5, 2018 | OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file ... |
| CVE-2018-5442 | CRITICAL | 9.8 | 3.8% | Feb 5, 2018 | A Stack-based Buffer Overflow issue was discovered in Fuji Electric V-Server VPR 4.0.1.0 and prior. The stack-based buff... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now