2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-21003——The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
CVE-2018-21002——The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
CVE-2018-21001——The anycomment plugin before 0.0.33 for WordPress has XSS.
CVE-2018-17557——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-20986. Reason: This candidate is a reservation d...
CVE-2018-18668——GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage t...
CVE-2018-20998——An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mis...
CVE-2018-20997——An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
CVE-2018-20996——An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor misha...
CVE-2018-20995——An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption be...
CVE-2018-20989——An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow an...
CVE-2018-21000——An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong o...
CVE-2018-20999——An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.
CVE-2018-20991——An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors,...
CVE-2018-20994——An issue was discovered in the trust-dns-proto crate before 0.5.0-alpha.3 for Rust. There is infinite recursion because ...
CVE-2018-20993——An issue was discovered in the yaml-rust crate before 0.4.1 for Rust. There is uncontrolled recursion during deserializa...
CVE-2018-20992——An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain d...
CVE-2018-20990——An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or har...
CVE-2018-13367——An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain pl...
CVE-2018-20987——The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
CVE-2018-20986——The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho...
CVE-2018-20988——The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
CVE-2018-18573——osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated adm...
CVE-2018-18572——osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, ...
CVE-2018-20985——The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay...
CVE-2018-20984——The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now