2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7911 | — | — | 0.2% | Oct 23, 2018 | Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C0... |
| CVE-2018-18329 | — | — | 0.6% | Oct 23, 2018 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer... |
| CVE-2018-18328 | — | — | 0.6% | Oct 23, 2018 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer... |
| CVE-2018-18327 | — | — | 0.6% | Oct 23, 2018 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer... |
| CVE-2018-15367 | — | — | 0.6% | Oct 23, 2018 | A ctl_set KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (... |
| CVE-2018-15366 | — | — | 0.5% | Oct 23, 2018 | A UrlfWTPPagePtr KERedirect Use-After-Free Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer... |
| CVE-2018-13402 | — | — | 1.4% | Oct 23, 2018 | Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 befor... |
| CVE-2018-13401 | — | — | 1.4% | Oct 23, 2018 | The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from versi... |
| CVE-2018-13400 | — | — | 1.4% | Oct 23, 2018 | Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from v... |
| CVE-2018-18587 | — | — | 0.5% | Oct 23, 2018 | BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash. |
| CVE-2018-18586 | — | — | 3.3% | Oct 23, 2018 | chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against a... |
| CVE-2018-18583 | — | — | 1.4% | Oct 22, 2018 | An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c d... |
| CVE-2018-18582 | — | — | 1.4% | Oct 22, 2018 | An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c d... |
| CVE-2018-18581 | — | — | 1.3% | Oct 22, 2018 | An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer over-read in internalPrintf in miniz/lupn... |
| CVE-2018-18579 | — | — | 0.7% | Oct 22, 2018 | Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter. |
| CVE-2018-18578 | — | — | 0.7% | Oct 22, 2018 | DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter. |
| CVE-2018-13115 | — | — | 1.0% | Oct 22, 2018 | Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the came... |
| CVE-2018-13114 | — | — | 1.9% | Oct 22, 2018 | Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute... |
| CVE-2018-15704 | — | — | 21.5% | Oct 22, 2018 | Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attac... |
| CVE-2018-15703 | — | — | 0.9% | Oct 22, 2018 | Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote u... |
| CVE-2018-12246 | — | — | 1.0% | Oct 22, 2018 | Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability... |
| CVE-2018-18557 | — | — | 15.0% | Oct 22, 2018 | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3... |
| CVE-2018-18553 | — | — | 0.9% | Oct 22, 2018 | Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page. |
| CVE-2018-18550 | — | — | 0.9% | Oct 21, 2018 | ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user. |
| CVE-2018-18546 | — | — | 1.7% | Oct 21, 2018 | ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder functi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now