2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6395 | — | — | 2.7% | Jan 30, 2018 | SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action. |
| CVE-2018-6382 | — | — | 0.5% | Jan 30, 2018 | MantisBT 2.10.0 allows local users to conduct SQL Injection attacks via the vendor/adodb/adodb-php/server.php sql parame... |
| CVE-2018-6393 | — | — | 2.2% | Jan 29, 2018 | FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order param... |
| CVE-2018-3835 | HIGH | 8.8 | 2.5% | Jan 29, 2018 | An exploitable out of bounds write vulnerability exists in version 2.2 of the Per Face Texture mapping application known... |
| CVE-2018-0101 | CRITICAL | 10 | 86.8% | Jan 29, 2018 | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw... |
| CVE-2018-6392 | — | — | 1.7% | Jan 29, 2018 | The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denia... |
| CVE-2018-6391 | — | — | 1.0% | Jan 29, 2018 | A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker... |
| CVE-2018-6390 | MEDIUM | 6.5 | 1.1% | Jan 29, 2018 | The WStr::assign function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 does not validate the size of th... |
| CVE-2018-6388 | — | — | 6.0% | Jan 29, 2018 | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands... |
| CVE-2018-6387 | — | — | 1.8% | Jan 29, 2018 | iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardc... |
| CVE-2018-6383 | HIGH | 8.8 | 13.6% | Jan 29, 2018 | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but ... |
| CVE-2018-6381 | — | — | 1.7% | Jan 29, 2018 | In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56... |
| CVE-2018-1364 | — | — | 2.4% | Jan 29, 2018 | IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data... |
| CVE-2018-6367 | — | — | 3.1% | Jan 29, 2018 | SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame... |
| CVE-2018-6365 | — | — | 3.1% | Jan 29, 2018 | SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php. |
| CVE-2018-6364 | — | — | 3.1% | Jan 29, 2018 | SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. |
| CVE-2018-6363 | CRITICAL | 9.8 | 3.0% | Jan 29, 2018 | SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter. |
| CVE-2018-6008 | — | — | 37.4% | Jan 29, 2018 | Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter... |
| CVE-2018-6007 | — | — | 2.3% | Jan 29, 2018 | CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket. |
| CVE-2018-5720 | — | — | 2.8% | Jan 29, 2018 | An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A C... |
| CVE-2018-6360 | — | — | 2.6% | Jan 28, 2018 | mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML docum... |
| CVE-2018-6359 | — | — | 2.5% | Jan 27, 2018 | The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow ... |
| CVE-2018-6358 | — | — | 1.9% | Jan 27, 2018 | The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, w... |
| CVE-2018-6357 | — | — | 0.7% | Jan 27, 2018 | The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordP... |
| CVE-2018-6354 | — | — | 0.8% | Jan 27, 2018 | templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now