2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-21003The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
CVE-2018-21002The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
CVE-2018-21001The anycomment plugin before 0.0.33 for WordPress has XSS.
CVE-2018-17557Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-20986. Reason: This candidate is a reservation d...
CVE-2018-18668GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage t...
CVE-2018-20998An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mis...
CVE-2018-20997An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
CVE-2018-20996An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor misha...
CVE-2018-20995An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption be...
CVE-2018-20989An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow an...
CVE-2018-21000An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong o...
CVE-2018-20999An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.
CVE-2018-20991An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors,...
CVE-2018-20994An issue was discovered in the trust-dns-proto crate before 0.5.0-alpha.3 for Rust. There is infinite recursion because ...
CVE-2018-20993An issue was discovered in the yaml-rust crate before 0.4.1 for Rust. There is uncontrolled recursion during deserializa...
CVE-2018-20992An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain d...
CVE-2018-20990An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or har...
CVE-2018-13367An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain pl...
CVE-2018-20987The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
CVE-2018-20986The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho...
CVE-2018-20988The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
CVE-2018-18573osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated adm...
CVE-2018-18572osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, ...
CVE-2018-20985The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay...
CVE-2018-20984The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now