2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-6307LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code ...
CVE-2018-20024LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that ...
CVE-2018-20023LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Re...
CVE-2018-20022LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vul...
CVE-2018-20021LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC cli...
CVE-2018-20020LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside stru...
CVE-2018-20019CRITICAL9.8LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities ...
CVE-2018-15127LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server c...
CVE-2018-15126LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code ...
CVE-2018-17195The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + ma...
CVE-2018-17194When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Lengt...
CVE-2018-17193The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resul...
CVE-2018-17192The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing securi...
CVE-2018-16883LOW2.5sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uid...
CVE-2018-20231Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote atta...
CVE-2018-20230An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in util...
CVE-2018-20228Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.
CVE-2018-20227HIGH7.5RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.
CVE-2018-19829Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary ...
CVE-2018-19790An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0...
CVE-2018-19789An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1...
CVE-2018-18921PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action.
CVE-2018-17777CRITICAL9.8An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the defaul...
CVE-2018-16884HIGH8A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the sa...
CVE-2018-6978vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now