2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6353 | — | — | 0.5% | Jan 27, 2018 | The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1... |
| CVE-2018-6352 | — | — | 1.0% | Jan 27, 2018 | In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. R... |
| CVE-2018-6015 | — | — | 3.3% | Jan 26, 2018 | An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST... |
| CVE-2018-5750 | — | — | 0.5% | Jan 26, 2018 | The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain ... |
| CVE-2018-0507 | — | — | 0.9% | Jan 26, 2018 | Untrusted search path vulnerability in FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.11 and earlier versions, FLE... |
| CVE-2018-0506 | — | — | 2.3% | Jan 26, 2018 | Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
| CVE-2018-6323 | — | — | 5.9% | Jan 26, 2018 | The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B... |
| CVE-2018-1342 | — | — | 1.2% | Jan 26, 2018 | A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially ... |
| CVE-2018-1000017 | — | — | — | Jan 26, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1142857. Reason: This candidate is effectively ... |
| CVE-2018-6315 | — | — | 2.5% | Jan 25, 2018 | The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow a... |
| CVE-2018-6313 | — | — | 0.6% | Jan 25, 2018 | Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script o... |
| CVE-2018-5447 | — | — | 2.5% | Jan 25, 2018 | An Improper Input Validation issue was discovered in Nari PCS-9611 relay. An improper input validation vulnerability has... |
| CVE-2018-1051 | — | — | 1.3% | Jan 25, 2018 | It was found that the fix for CVE-2016-9606 in versions 3.0.22 and 3.1.2 was incomplete and Yaml unmarshalling in Restea... |
| CVE-2018-5997 | — | — | 23.9% | Jan 25, 2018 | An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a pa... |
| CVE-2018-5973 | — | — | 20.5% | Jan 25, 2018 | SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, ... |
| CVE-2018-5965 | — | — | 1.3% | Jan 25, 2018 | CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter. |
| CVE-2018-5964 | — | — | 1.1% | Jan 25, 2018 | CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter. |
| CVE-2018-5963 | — | — | 1.3% | Jan 25, 2018 | CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/addbookmark.php via the title parameter. |
| CVE-2018-5954 | — | — | 9.1% | Jan 25, 2018 | phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect co... |
| CVE-2018-5748 | — | — | 3.2% | Jan 25, 2018 | qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply... |
| CVE-2018-4837 | — | — | 2.7% | Jan 25, 2018 | A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Serve... |
| CVE-2018-4836 | — | — | 1.8% | Jan 25, 2018 | A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged ... |
| CVE-2018-4835 | — | — | 2.2% | Jan 25, 2018 | A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleContr... |
| CVE-2018-6308 | — | — | 1.1% | Jan 25, 2018 | Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaign... |
| CVE-2018-6217 | — | — | 0.9% | Jan 25, 2018 | The WStr::_alloc_iostr_data() function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 allows remote attac... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now