2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19895ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the ma...
CVE-2018-19894ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is expl...
CVE-2018-19893SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.
CVE-2018-19892DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.
CVE-2018-19891An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud...
CVE-2018-19890An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud...
CVE-2018-19889An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud...
CVE-2018-19888An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud...
CVE-2018-19887An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud...
CVE-2018-19886MEDIUM5.5An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud...
CVE-2018-19882In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of servic...
CVE-2018-19881In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by...
CVE-2018-19754Tarantella Enterprise before 3.11 allows bypassing Access Control.
CVE-2018-19753Tarantella Enterprise before 3.11 allows Directory Traversal.
CVE-2018-19650Local attackers can trigger a stack-based buffer overflow on vulnerable installations of Antiy-AVL ATool security manage...
CVE-2018-19608Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintex...
CVE-2018-18312Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid...
CVE-2018-16792CRITICAL9.1SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file ...
CVE-2018-16791In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user...
CVE-2018-19877login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
CVE-2018-12155Data leakage in cryptographic libraries for Intel IPP before 2019 update1 release may allow an authenticated user to pot...
CVE-2018-1002105CRITICAL9.8In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg...
CVE-2018-1002103HIGH8.1In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM...
CVE-2018-1002101MEDIUM5.9In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up...
CVE-2018-19876cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible wi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now