2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19516MEDIUM5.3messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restric...
CVE-2018-10704MEDIUM6.1yidashi yii2cmf 2.0 has XSS via the /search q parameter.
CVE-2018-18894HIGH7.5Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the ...
CVE-2018-14502CRITICAL9.8controllers/quizzes.php in the Kiboko Chained Quiz plugin before 1.0.9 for WordPress allows remote unauthenticated users...
CVE-2018-11838HIGH7.8Possible double free issue in WLAN due to lack of checking memory free condition. in Snapdragon Auto, Snapdragon Compute...
CVE-2018-5951HIGH7.5An issue was discovered in Mikrotik RouterOS. Crafting a packet that has a size of 1 byte and sending it to an IPv6 addr...
CVE-2018-20347Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2018-20343HIGH7.8Multiple buffer overflow vulnerabilities have been found in Ken Silverman Build Engine 1. An attacker could craft a spec...
CVE-2018-19798HIGH8.8Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the applicatio...
CVE-2018-19658MEDIUM5.4The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote user...
CVE-2018-19599MEDIUM5.4Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: ...
CVE-2018-19284Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2018-18479Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2018-17572MEDIUM4.8InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
CVE-2018-16357CRITICAL9.8An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.
CVE-2018-16356CRITICAL9.8An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
CVE-2018-15820MEDIUM6.1EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.
CVE-2018-15819HIGH7.5EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
CVE-2018-14384MEDIUM4.8The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerabil...
CVE-2018-11675Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-17058HIGH8.8An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerabilit...
CVE-2018-21035HIGH7.5In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits can...
CVE-2018-8878MEDIUM5.3Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382...
CVE-2018-8877MEDIUM5.3Information disclosure in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382...
CVE-2018-19668Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-17963. Reason: This candidate is a reservation d...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now