2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-17965ImageMagick 7.0.7-28 has a memory leak vulnerability in WriteSGIImage in coders/sgi.c.
CVE-2018-17054Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows...
CVE-2018-17053Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows...
CVE-2018-12087Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attacker...
CVE-2018-16051An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x befor...
CVE-2018-16050An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There ...
CVE-2018-16049An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x befor...
CVE-2018-16048An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x befor...
CVE-2018-14800Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application...
CVE-2018-17947The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter.
CVE-2018-17946The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Gallerye...
CVE-2018-17942The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because mem...
CVE-2018-17938Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
CVE-2018-14826Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass ...
CVE-2018-14822Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has...
CVE-2018-9515In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co...
CVE-2018-9514In sdcardfs_open of file.c, there is a possible Use After Free due to an unusual root cause. This could lead to local es...
CVE-2018-9513In copy_process of fork.c, there is possible memory corruption due to a double free. This could lead to local escalation...
CVE-2018-9511In ipSecSetEncapSocketOwner of XfrmController.cpp, there is a possible failure to initialize a security feature due to u...
CVE-2018-9510In smp_proc_enc_info of smp_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lea...
CVE-2018-9509In smp_proc_master_id of smp_act.cc, there is a possible out of bounds read due to a missing bounds check. This could le...
CVE-2018-9508In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds ch...
CVE-2018-9507In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This ...
CVE-2018-9506In avrc_msg_cback of avrc_api.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead t...
CVE-2018-9505In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds check. This could lead...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now