2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15768 | — | — | 9.1% | Nov 30, 2018 | Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due... |
| CVE-2018-15767 | — | — | 12.3% | Nov 30, 2018 | The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerab... |
| CVE-2018-9072 | — | — | 0.9% | Nov 30, 2018 | In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient i... |
| CVE-2018-16097 | — | — | 0.5% | Nov 30, 2018 | LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated... |
| CVE-2018-16093 | — | — | 0.7% | Nov 30, 2018 | In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient s... |
| CVE-2018-0716 | — | — | 0.8% | Nov 30, 2018 | Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central... |
| CVE-2018-19777 | — | — | 1.1% | Nov 30, 2018 | In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrate... |
| CVE-2018-19764 | — | — | — | Nov 30, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-19763 | — | — | 0.7% | Nov 30, 2018 | There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a den... |
| CVE-2018-19762 | — | — | 0.8% | Nov 30, 2018 | There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a... |
| CVE-2018-19761 | — | — | 0.7% | Nov 30, 2018 | There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a ... |
| CVE-2018-19760 | — | — | 1.1% | Nov 30, 2018 | cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak. |
| CVE-2018-19759 | — | — | 0.7% | Nov 30, 2018 | There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that wil... |
| CVE-2018-19758 | — | — | 1.7% | Nov 30, 2018 | There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of ser... |
| CVE-2018-19757 | — | — | 0.9% | Nov 30, 2018 | There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that wi... |
| CVE-2018-19756 | — | — | 0.7% | Nov 30, 2018 | There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a den... |
| CVE-2018-19755 | — | — | 1.0% | Nov 30, 2018 | There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will... |
| CVE-2018-19527 | — | — | 0.7% | Nov 29, 2018 | i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings. |
| CVE-2018-1000819 | — | — | — | Nov 29, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-19131. Reason: This candidate is a reservation... |
| CVE-2018-1000818 | — | — | — | Nov 29, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-19132. Reason: This candidate is a reservation... |
| CVE-2018-19752 | — | — | 3.3% | Nov 29, 2018 | DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar. |
| CVE-2018-19751 | — | — | 3.3% | Nov 29, 2018 | DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields. |
| CVE-2018-19750 | — | — | 1.8% | Nov 29, 2018 | DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma... |
| CVE-2018-19749 | — | — | 3.3% | Nov 29, 2018 | DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field. |
| CVE-2018-18619 | — | — | 4.2% | Nov 29, 2018 | internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability bec... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now