2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-1000662Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was inadvertently assigned...
CVE-2018-6923In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial ...
CVE-2018-6555The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel b...
CVE-2018-6554Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux...
CVE-2018-7990Mate10 Pro Huawei smart phones with the versions before 8.1.0.326(C00) have a FRP bypass vulnerability. During the mobil...
CVE-2018-7938P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the ...
CVE-2018-7937In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-...
CVE-2018-7936Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) b...
CVE-2018-11262In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while ...
CVE-2018-0675AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.
CVE-2018-0674AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors.
CVE-2018-0672Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitr...
CVE-2018-0664A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unsp...
CVE-2018-0656Untrusted search path vulnerability in The installer of Digital Paper App version 1.4.0.16050 and earlier allows an atta...
CVE-2018-0646Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecifie...
CVE-2018-16458An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication o...
CVE-2018-16450CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
CVE-2018-16449OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Arti...
CVE-2018-16448Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.ph...
CVE-2018-16447Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
CVE-2018-16446An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary fil...
CVE-2018-16445An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.p...
CVE-2018-16444An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
CVE-2018-16438An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexterna...
CVE-2018-16435Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats....

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now