2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-19416An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a m...
CVE-2018-19411PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user wi...
CVE-2018-19409An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device ...
CVE-2018-19407The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a den...
CVE-2018-19406kvm_pv_send_ipi in arch/x86/kvm/lapic.c in the Linux kernel through 4.19.2 allows local users to cause a denial of servi...
CVE-2018-19404In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to exe...
CVE-2018-19396ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application cra...
CVE-2018-19395ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to cause a denial of service (NULL pointer dere...
CVE-2018-19390FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exce...
CVE-2018-19389FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exce...
CVE-2018-19388FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read, ac...
CVE-2018-19387Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-19376An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file ...
CVE-2018-18865The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13...
CVE-2018-18864Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.
CVE-2018-18861Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
CVE-2018-18859Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS....
CVE-2018-18858Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS....
CVE-2018-18857Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS....
CVE-2018-18856Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS....
CVE-2018-18774CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
CVE-2018-18773CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demo...
CVE-2018-18772CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem...
CVE-2018-18716Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
CVE-2018-18715Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now