2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11020kernel/omap/drivers/rpmsg/rpmsg_omx.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attac...
CVE-2018-11019kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows...
CVE-2018-18389Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authenti...
CVE-2018-18385Asciidoctor in versions < 1.5.8 allows remote attackers to cause a denial of service (infinite loop). The loop was cause...
CVE-2018-18384Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed...
CVE-2018-13399The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escala...
CVE-2018-18382Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can ...
CVE-2018-18377goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which ...
CVE-2018-18376goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about current...
CVE-2018-18375goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, an...
CVE-2018-18374XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
CVE-2018-18260In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can b...
CVE-2018-18259Stored XSS has been discovered in version 1.0.12 of the LUYA CMS software via /admin/api-cms-nav/create-page.
CVE-2018-17980NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo...
CVE-2018-17534Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper acc...
CVE-2018-17533Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlog...
CVE-2018-17532Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulne...
CVE-2018-15540Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse t...
CVE-2018-15539Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc...
CVE-2018-15538Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
CVE-2018-12154Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5...
CVE-2018-15378A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition...
CVE-2018-17961Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err...
CVE-2018-15593An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c...
CVE-2018-15592An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now