2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-21003 | — | — | 1.8% | Aug 27, 2019 | The buddyforms plugin before 2.2.8 for WordPress has SQL injection. |
| CVE-2018-21002 | — | — | 0.7% | Aug 27, 2019 | The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. |
| CVE-2018-21001 | — | — | 0.9% | Aug 27, 2019 | The anycomment plugin before 0.0.33 for WordPress has XSS. |
| CVE-2018-17557 | — | — | — | Aug 27, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-20986. Reason: This candidate is a reservation d... |
| CVE-2018-18668 | — | — | 1.4% | Aug 26, 2019 | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage t... |
| CVE-2018-20998 | — | — | 1.6% | Aug 26, 2019 | An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mis... |
| CVE-2018-20997 | — | — | 1.7% | Aug 26, 2019 | An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing. |
| CVE-2018-20996 | — | — | 1.7% | Aug 26, 2019 | An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor misha... |
| CVE-2018-20995 | — | — | 1.6% | Aug 26, 2019 | An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption be... |
| CVE-2018-20989 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow an... |
| CVE-2018-21000 | — | — | 2.0% | Aug 26, 2019 | An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong o... |
| CVE-2018-20999 | — | — | 1.6% | Aug 26, 2019 | An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results. |
| CVE-2018-20991 | — | — | 1.8% | Aug 26, 2019 | An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors,... |
| CVE-2018-20994 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the trust-dns-proto crate before 0.5.0-alpha.3 for Rust. There is infinite recursion because ... |
| CVE-2018-20993 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the yaml-rust crate before 0.4.1 for Rust. There is uncontrolled recursion during deserializa... |
| CVE-2018-20992 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain d... |
| CVE-2018-20990 | — | — | 1.7% | Aug 26, 2019 | An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or har... |
| CVE-2018-13367 | — | — | 0.9% | Aug 23, 2019 | An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain pl... |
| CVE-2018-20987 | — | — | 2.1% | Aug 22, 2019 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. |
| CVE-2018-20986 | — | — | 0.9% | Aug 22, 2019 | The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho... |
| CVE-2018-20988 | — | — | 1.4% | Aug 22, 2019 | The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation. |
| CVE-2018-18573 | — | — | 2.5% | Aug 22, 2019 | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated adm... |
| CVE-2018-18572 | — | — | 2.5% | Aug 22, 2019 | osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, ... |
| CVE-2018-20985 | — | — | 7.6% | Aug 22, 2019 | The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay... |
| CVE-2018-20984 | — | — | 2.0% | Aug 22, 2019 | The patreon-connect plugin before 1.2.2 for WordPress has Object Injection. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now