2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19994 | — | — | 2.0% | Jan 3, 2019 | An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated use... |
| CVE-2018-19993 | — | — | 1.4% | Jan 3, 2019 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web s... |
| CVE-2018-19992 | — | — | 1.1% | Jan 3, 2019 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrar... |
| CVE-2018-19862 | — | — | 12.6% | Jan 3, 2019 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re... |
| CVE-2018-19861 | — | — | 12.6% | Jan 3, 2019 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re... |
| CVE-2018-19523 | — | — | 0.3% | Jan 3, 2019 | DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user ... |
| CVE-2018-19505 | — | — | 1.6% | Jan 3, 2019 | Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, w... |
| CVE-2018-19415 | — | — | 1.5% | Jan 3, 2019 | Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via ... |
| CVE-2018-19414 | — | — | 2.2% | Jan 3, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to inject arbitrary web s... |
| CVE-2018-14481 | — | — | 1.1% | Jan 3, 2019 | Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280. |
| CVE-2018-17161 | — | — | 3.5% | Jan 3, 2019 | In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validat... |
| CVE-2018-16885 | MEDIUM | 4.7 | 0.4% | Jan 3, 2019 | A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with ... |
| CVE-2018-16882 | HIGH | 8.8 | 0.4% | Jan 3, 2019 | A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1... |
| CVE-2018-16870 | — | — | 1.6% | Jan 3, 2019 | It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade... |
| CVE-2018-16876 | MEDIUM | 5.3 | 2.5% | Jan 3, 2019 | ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on... |
| CVE-2018-16879 | CRITICAL | 9.8 | 1.1% | Jan 3, 2019 | Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration chann... |
| CVE-2018-20662 | MEDIUM | 6.5 | 2.2% | Jan 3, 2019 | In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by... |
| CVE-2018-17172 | — | — | 2.0% | Jan 3, 2019 | The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 ... |
| CVE-2018-20131 | — | — | 0.3% | Jan 3, 2019 | The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on t... |
| CVE-2018-18893 | — | — | 1.8% | Jan 3, 2019 | Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.jav... |
| CVE-2018-18264 | — | — | 70.4% | Jan 3, 2019 | Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for rea... |
| CVE-2018-20326 | — | — | 4.8% | Jan 2, 2019 | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage... |
| CVE-2018-20211 | — | — | 1.4% | Jan 2, 2019 | ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with ... |
| CVE-2018-20166 | — | — | 7.1% | Jan 2, 2019 | A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a... |
| CVE-2018-20114 | CRITICAL | 9.8 | 6.7% | Jan 2, 2019 | On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now