2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-20635PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directo...
CVE-2018-20634PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) ...
CVE-2018-20633PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
CVE-2018-20632PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field.
CVE-2018-20631PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such a...
CVE-2018-20630PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uplo...
CVE-2018-20629PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing o...
CVE-2018-20628PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of ...
CVE-2018-20627PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.
CVE-2018-20626PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads ...
CVE-2018-20615An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which...
CVE-2018-20556SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary ...
CVE-2018-20555The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_to...
CVE-2018-20526Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
CVE-2018-20340Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer ...
CVE-2018-20323www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitra...
CVE-2018-20221Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ...
CVE-2018-20220An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authen...
CVE-2018-20219An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the de...
CVE-2018-20218An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input direct...
CVE-2018-20212bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
CVE-2018-20162Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' ...
CVE-2018-20141AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--access...
CVE-2018-20140Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.
CVE-2018-20121Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now