2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-20635——PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directo...
CVE-2018-20634——PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) ...
CVE-2018-20633——PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
CVE-2018-20632——PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field.
CVE-2018-20631——PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such a...
CVE-2018-20630——PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uplo...
CVE-2018-20629——PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing o...
CVE-2018-20628——PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of ...
CVE-2018-20627——PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.
CVE-2018-20626——PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads ...
CVE-2018-20615——An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which...
CVE-2018-20556——SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary ...
CVE-2018-20555——The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_to...
CVE-2018-20526——Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
CVE-2018-20340——Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer ...
CVE-2018-20323——www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitra...
CVE-2018-20221——Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ...
CVE-2018-20220——An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authen...
CVE-2018-20219——An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the de...
CVE-2018-20218——An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input direct...
CVE-2018-20212——bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
CVE-2018-20162——Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' ...
CVE-2018-20141——AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--access...
CVE-2018-20140——Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.
CVE-2018-20121——Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now