2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19895 | — | — | 1.3% | Dec 6, 2018 | ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the ma... |
| CVE-2018-19894 | — | — | 1.3% | Dec 6, 2018 | ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is expl... |
| CVE-2018-19893 | — | — | 1.1% | Dec 6, 2018 | SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string. |
| CVE-2018-19892 | — | — | 1.5% | Dec 6, 2018 | DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field. |
| CVE-2018-19891 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19890 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19889 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19888 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19887 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19886 | MEDIUM | 5.5 | 1.0% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19882 | — | — | 1.4% | Dec 6, 2018 | In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of servic... |
| CVE-2018-19881 | — | — | 1.6% | Dec 6, 2018 | In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by... |
| CVE-2018-19754 | — | — | 2.6% | Dec 5, 2018 | Tarantella Enterprise before 3.11 allows bypassing Access Control. |
| CVE-2018-19753 | — | — | 16.6% | Dec 5, 2018 | Tarantella Enterprise before 3.11 allows Directory Traversal. |
| CVE-2018-19650 | — | — | 0.6% | Dec 5, 2018 | Local attackers can trigger a stack-based buffer overflow on vulnerable installations of Antiy-AVL ATool security manage... |
| CVE-2018-19608 | — | — | 0.3% | Dec 5, 2018 | Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintex... |
| CVE-2018-18312 | — | — | 12.1% | Dec 5, 2018 | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid... |
| CVE-2018-16792 | CRITICAL | 9.1 | 1.4% | Dec 5, 2018 | SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file ... |
| CVE-2018-16791 | — | — | 1.5% | Dec 5, 2018 | In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user... |
| CVE-2018-19877 | — | — | 18.6% | Dec 5, 2018 | login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. |
| CVE-2018-12155 | — | — | 0.3% | Dec 5, 2018 | Data leakage in cryptographic libraries for Intel IPP before 2019 update1 release may allow an authenticated user to pot... |
| CVE-2018-1002105 | CRITICAL | 9.8 | 87.0% | Dec 5, 2018 | In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg... |
| CVE-2018-1002103 | HIGH | 8.1 | 0.7% | Dec 5, 2018 | In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM... |
| CVE-2018-1002101 | MEDIUM | 5.9 | 4.1% | Dec 5, 2018 | In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up... |
| CVE-2018-19876 | — | — | 1.7% | Dec 5, 2018 | cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible wi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now