2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5759 | — | — | 5.2% | Jan 24, 2018 | jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re... |
| CVE-2018-5705 | — | — | 1.5% | Jan 24, 2018 | Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to t... |
| CVE-2018-4834 | CRITICAL | 9.8 | 3.4% | Jan 24, 2018 | A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All ve... |
| CVE-2018-6018 | — | — | 1.0% | Jan 24, 2018 | Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive i... |
| CVE-2018-6017 | — | — | 1.0% | Jan 24, 2018 | Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensit... |
| CVE-2018-5778 | — | — | 1.1% | Jan 24, 2018 | An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities a... |
| CVE-2018-5777 | — | — | 1.7% | Jan 24, 2018 | An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a m... |
| CVE-2018-5319 | — | — | 12.6% | Jan 24, 2018 | RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request. |
| CVE-2018-1000018 | — | — | 0.4% | Jan 24, 2018 | An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file. |
| CVE-2018-6187 | — | — | 1.9% | Jan 24, 2018 | In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the... |
| CVE-2018-6184 | — | — | 9.2% | Jan 24, 2018 | ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace. |
| CVE-2018-5988 | — | — | 19.5% | Jan 24, 2018 | SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php. |
| CVE-2018-5986 | CRITICAL | 9.8 | 2.6% | Jan 24, 2018 | SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php. |
| CVE-2018-5985 | — | — | 19.5% | Jan 24, 2018 | SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request. |
| CVE-2018-5984 | — | — | 2.7% | Jan 24, 2018 | SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the categor... |
| CVE-2018-5979 | — | — | 15.5% | Jan 24, 2018 | SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field. |
| CVE-2018-5978 | — | — | 2.7% | Jan 24, 2018 | SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field. |
| CVE-2018-5977 | — | — | 2.0% | Jan 24, 2018 | SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= r... |
| CVE-2018-5976 | — | — | 2.2% | Jan 24, 2018 | Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi... |
| CVE-2018-5972 | — | — | 19.5% | Jan 24, 2018 | SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listin... |
| CVE-2018-5969 | — | — | 1.4% | Jan 24, 2018 | Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demons... |
| CVE-2018-5749 | — | — | 2.5% | Jan 23, 2018 | install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does no... |
| CVE-2018-5683 | MEDIUM | 6 | 0.7% | Jan 23, 2018 | The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds re... |
| CVE-2018-5359 | — | — | 9.2% | Jan 23, 2018 | The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system... |
| CVE-2018-5950 | MEDIUM | 6.1 | 4.6% | Jan 23, 2018 | Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitr... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now