2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000016 | — | — | — | Jan 23, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17383. Reason: This candidate is a reservation... |
| CVE-2018-1000015 | — | — | 1.1% | Jan 23, 2018 | On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Bui... |
| CVE-2018-1000014 | — | — | 0.8% | Jan 23, 2018 | Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, result... |
| CVE-2018-1000013 | — | — | 1.0% | Jan 23, 2018 | Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vu... |
| CVE-2018-1000012 | — | — | 1.0% | Jan 23, 2018 | Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process... |
| CVE-2018-1000011 | — | — | 1.0% | Jan 23, 2018 | Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process... |
| CVE-2018-1000010 | — | — | 1.0% | Jan 23, 2018 | Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, all... |
| CVE-2018-1000009 | — | — | 1.0% | Jan 23, 2018 | Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build proce... |
| CVE-2018-1000008 | — | — | 1.2% | Jan 23, 2018 | Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, all... |
| CVE-2018-6029 | — | — | 1.4% | Jan 23, 2018 | The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the con... |
| CVE-2018-6022 | — | — | 1.4% | Jan 23, 2018 | Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authen... |
| CVE-2018-6014 | — | — | 1.3% | Jan 23, 2018 | Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrie... |
| CVE-2018-6013 | — | — | 0.9% | Jan 23, 2018 | Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the dire... |
| CVE-2018-0862 | — | — | 19.0% | Jan 22, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro... |
| CVE-2018-0849 | — | — | 19.0% | Jan 22, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro... |
| CVE-2018-0848 | — | — | 20.9% | Jan 22, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro... |
| CVE-2018-0845 | — | — | 20.1% | Jan 22, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Micro... |
| CVE-2018-6010 | — | — | 2.9% | Jan 22, 2018 | In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messa... |
| CVE-2018-6009 | — | — | 0.6% | Jan 22, 2018 | In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a... |
| CVE-2018-6003 | HIGH | 7.5 | 2.8% | Jan 22, 2018 | An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited rec... |
| CVE-2018-6002 | — | — | 0.8% | Jan 22, 2018 | The Soundy Background Music plugin 3.9 and below for WordPress has Cross-Site Scripting via soundy-background-music\temp... |
| CVE-2018-6001 | — | — | 0.8% | Jan 22, 2018 | The Soundy Audio Playlist plugin 4.6 and below for WordPress has Cross-Site Scripting via soundy-audio-playlist\template... |
| CVE-2018-6000 | — | — | 84.5% | Jan 22, 2018 | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn... |
| CVE-2018-5999 | — | — | 87.4% | Jan 22, 2018 | An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro... |
| CVE-2018-1000003 | — | — | 1.3% | Jan 22, 2018 | Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-mi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now