2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14663MEDIUM5.9An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing d...
CVE-2018-13324Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by...
CVE-2018-13323Cross-site scripting in detail.html in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute JavaScript via ...
CVE-2018-13322Directory traversal in list_folders method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to list directory c...
CVE-2018-13321Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal ...
CVE-2018-13320System Command Injection in network.set_auth_settings in Buffalo TS5600D1206 version 3.70-0.10 allows attackers to execu...
CVE-2018-13319Incorrect access control in get_portal_info in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to determine sensi...
CVE-2018-13318System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute syst...
CVE-2018-13317Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password ...
CVE-2018-13315Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin use...
CVE-2018-13312Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScrip...
CVE-2018-13311System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via t...
CVE-2018-13310Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript ...
CVE-2018-13309Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript ...
CVE-2018-13308Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScrip...
CVE-2018-19568A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malici...
CVE-2018-19567A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious f...
CVE-2018-19566A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious file...
CVE-2018-19565A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files...
CVE-2018-18807HIGH7.6The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerab...
CVE-2018-11077'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and...
CVE-2018-11076Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appl...
CVE-2018-11067Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1...
CVE-2018-11066Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1...
CVE-2018-16862MEDIUM5.3A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final fil...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now