2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14663 | MEDIUM | 5.9 | 2.5% | Nov 26, 2018 | An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing d... |
| CVE-2018-13324 | — | — | 23.2% | Nov 26, 2018 | Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by... |
| CVE-2018-13323 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in detail.html in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute JavaScript via ... |
| CVE-2018-13322 | — | — | 1.3% | Nov 26, 2018 | Directory traversal in list_folders method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to list directory c... |
| CVE-2018-13321 | — | — | 1.0% | Nov 26, 2018 | Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal ... |
| CVE-2018-13320 | — | — | 2.8% | Nov 26, 2018 | System Command Injection in network.set_auth_settings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execu... |
| CVE-2018-13319 | — | — | 1.2% | Nov 26, 2018 | Incorrect access control in get_portal_info in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to determine sensi... |
| CVE-2018-13318 | — | — | 2.8% | Nov 26, 2018 | System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute syst... |
| CVE-2018-13317 | — | — | 1.0% | Nov 26, 2018 | Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password ... |
| CVE-2018-13315 | — | — | 1.6% | Nov 26, 2018 | Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin use... |
| CVE-2018-13312 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScrip... |
| CVE-2018-13311 | — | — | 2.5% | Nov 26, 2018 | System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via t... |
| CVE-2018-13310 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript ... |
| CVE-2018-13309 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript ... |
| CVE-2018-13308 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScrip... |
| CVE-2018-19568 | — | — | 0.9% | Nov 26, 2018 | A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malici... |
| CVE-2018-19567 | — | — | 0.9% | Nov 26, 2018 | A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious f... |
| CVE-2018-19566 | — | — | 1.1% | Nov 26, 2018 | A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious file... |
| CVE-2018-19565 | — | — | 1.1% | Nov 26, 2018 | A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files... |
| CVE-2018-18807 | HIGH | 7.6 | 1.2% | Nov 26, 2018 | The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerab... |
| CVE-2018-11077 | — | — | 1.0% | Nov 26, 2018 | 'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and... |
| CVE-2018-11076 | — | — | 0.8% | Nov 26, 2018 | Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appl... |
| CVE-2018-11067 | — | — | 1.8% | Nov 26, 2018 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1... |
| CVE-2018-11066 | — | — | 9.9% | Nov 26, 2018 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1... |
| CVE-2018-16862 | MEDIUM | 5.3 | 0.5% | Nov 26, 2018 | A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final fil... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now