2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-5365The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter...
CVE-2018-5364The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] paramete...
CVE-2018-5363The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enable...
CVE-2018-5362The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.p...
CVE-2018-5361The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.
CVE-2018-5358ImageMagick 7.0.7-22 Q16 has memory leaks in the EncodeImageAttributes function in coders/json.c, as demonstrated by the...
CVE-2018-5357ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.
CVE-2018-5344In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to...
CVE-2018-5327Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allow...
CVE-2018-5326Cheetah Mobile CM Browser 5.22.06.0012, when installed on unspecified "older" Android platforms, allows Same Origin Poli...
CVE-2018-5347Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs ...
CVE-2018-5345A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash o...
CVE-2018-5336In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addr...
CVE-2018-5335In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/pa...
CVE-2018-5334In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/v...
CVE-2018-1361IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra...
CVE-2018-5189Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain syste...
CVE-2018-0118A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthentic...
CVE-2018-5333In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning ...
CVE-2018-5332HIGH7.8In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA ...
CVE-2018-0014MEDIUM4.3Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of...
CVE-2018-0013MEDIUM6.5A local file inclusion vulnerability in Juniper Networks Junos Space Network Management Platform may allow an authentica...
CVE-2018-0012HIGH7.8Junos Space is affected by a privilege escalation vulnerability that may allow a local authenticated attacker to gain ro...
CVE-2018-0011MEDIUM5.4A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to...
CVE-2018-0010A vulnerability in the Juniper Networks Junos Space Security Director allows a user who does not have SSH access to a de...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now