2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15816 | — | — | 0.8% | Mar 26, 2019 | FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d7d v... |
| CVE-2018-15815 | — | — | 0.8% | Mar 26, 2019 | FastStone Image Viewer 6.5 has an Exception Handler Chain Corrupted issue starting at image00400000+0x00000000003ef68a v... |
| CVE-2018-15814 | — | — | 0.8% | Mar 26, 2019 | FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image fil... |
| CVE-2018-15813 | — | — | 0.8% | Mar 26, 2019 | FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000000e1237 via a crafted image fil... |
| CVE-2018-19856 | — | — | 2.3% | Mar 26, 2019 | GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API... |
| CVE-2018-12653 | — | — | 2.6% | Mar 25, 2019 | A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious Jav... |
| CVE-2018-12652 | — | — | 0.9% | Mar 25, 2019 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied in... |
| CVE-2018-20165 | — | — | 1.5% | Mar 22, 2019 | Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script... |
| CVE-2018-13798 | — | — | 2.0% | Mar 21, 2019 | A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V14), SICAM A8000 CP-802X (All versions < V14... |
| CVE-2018-6517 | — | — | 0.9% | Mar 21, 2019 | Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting add... |
| CVE-2018-20737 | — | — | 1.0% | Mar 21, 2019 | An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product. |
| CVE-2018-20736 | — | — | 1.0% | Mar 21, 2019 | An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product. |
| CVE-2018-20648 | — | — | 0.6% | Mar 21, 2019 | PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php. |
| CVE-2018-20647 | — | — | 1.9% | Mar 21, 2019 | PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image director... |
| CVE-2018-20646 | — | — | 1.7% | Mar 21, 2019 | PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image direc... |
| CVE-2018-20645 | — | — | 0.7% | Mar 21, 2019 | PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field. |
| CVE-2018-20644 | — | — | 0.7% | Mar 21, 2019 | PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature. |
| CVE-2018-20643 | — | — | 1.7% | Mar 21, 2019 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an i... |
| CVE-2018-20642 | — | — | 1.6% | Mar 21, 2019 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 allows remote attackers to cause a denial of service (outage of pr... |
| CVE-2018-20641 | — | — | 0.6% | Mar 21, 2019 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature... |
| CVE-2018-20640 | — | — | 0.7% | Mar 21, 2019 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field. |
| CVE-2018-20639 | — | — | 0.8% | Mar 21, 2019 | PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar. |
| CVE-2018-20638 | — | — | 1.5% | Mar 21, 2019 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing... |
| CVE-2018-20637 | — | — | 1.6% | Mar 21, 2019 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unre... |
| CVE-2018-20636 | — | — | 0.7% | Mar 21, 2019 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now