2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20635 | — | — | 1.3% | Mar 21, 2019 | PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directo... |
| CVE-2018-20634 | — | — | 1.6% | Mar 21, 2019 | PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) ... |
| CVE-2018-20633 | — | — | 0.7% | Mar 21, 2019 | PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. |
| CVE-2018-20632 | — | — | 0.7% | Mar 21, 2019 | PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field. |
| CVE-2018-20631 | — | — | 1.6% | Mar 21, 2019 | PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such a... |
| CVE-2018-20630 | — | — | 1.9% | Mar 21, 2019 | PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uplo... |
| CVE-2018-20629 | — | — | 1.9% | Mar 21, 2019 | PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing o... |
| CVE-2018-20628 | — | — | 2.2% | Mar 21, 2019 | PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of ... |
| CVE-2018-20627 | — | — | 0.7% | Mar 21, 2019 | PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box. |
| CVE-2018-20626 | — | — | 1.7% | Mar 21, 2019 | PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads ... |
| CVE-2018-20615 | — | — | 4.5% | Mar 21, 2019 | An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which... |
| CVE-2018-20556 | — | — | 19.2% | Mar 21, 2019 | SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary ... |
| CVE-2018-20555 | — | — | 10.4% | Mar 21, 2019 | The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_to... |
| CVE-2018-20526 | — | — | 73.7% | Mar 21, 2019 | Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. |
| CVE-2018-20340 | — | — | 0.5% | Mar 21, 2019 | Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer ... |
| CVE-2018-20323 | — | — | 55.1% | Mar 21, 2019 | www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitra... |
| CVE-2018-20221 | — | — | 10.5% | Mar 21, 2019 | Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ... |
| CVE-2018-20220 | — | — | 15.4% | Mar 21, 2019 | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authen... |
| CVE-2018-20219 | — | — | 14.6% | Mar 21, 2019 | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the de... |
| CVE-2018-20218 | — | — | 10.7% | Mar 21, 2019 | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input direct... |
| CVE-2018-20212 | — | — | 1.6% | Mar 21, 2019 | bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter. |
| CVE-2018-20162 | — | — | 4.2% | Mar 21, 2019 | Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' ... |
| CVE-2018-20141 | — | — | 1.6% | Mar 21, 2019 | AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--access... |
| CVE-2018-20140 | — | — | 1.6% | Mar 21, 2019 | Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters. |
| CVE-2018-20121 | — | — | 1.6% | Mar 21, 2019 | Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now