2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15454 | HIGH | 8.6 | 4.4% | Nov 1, 2018 | A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) So... |
| CVE-2018-18892 | — | — | 2.6% | Nov 1, 2018 | MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name ... |
| CVE-2018-18891 | — | — | 1.2% | Nov 1, 2018 | MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs to... |
| CVE-2018-18890 | — | — | 1.5% | Nov 1, 2018 | MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename. |
| CVE-2018-18888 | — | — | 1.3% | Nov 1, 2018 | An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upl... |
| CVE-2018-18887 | — | — | 1.1% | Nov 1, 2018 | S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field). |
| CVE-2018-18883 | — | — | 0.4% | Nov 1, 2018 | An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a ... |
| CVE-2018-15707 | — | — | 1.9% | Oct 31, 2018 | Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could... |
| CVE-2018-15706 | — | — | 32.4% | Oct 31, 2018 | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the fil... |
| CVE-2018-15705 | — | — | 12.2% | Oct 31, 2018 | WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f... |
| CVE-2018-14651 | HIGH | 8.8 | 3.2% | Oct 31, 2018 | It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was inc... |
| CVE-2018-14661 | MEDIUM | 6.5 | 2.7% | Oct 31, 2018 | It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red ... |
| CVE-2018-11759 | — | — | 90.6% | Oct 31, 2018 | The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map ... |
| CVE-2018-16842 | MEDIUM | 4.4 | 2.1% | Oct 31, 2018 | Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function ... |
| CVE-2018-14659 | MEDIUM | 6.5 | 2.2% | Oct 31, 2018 | The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_... |
| CVE-2018-14654 | MEDIUM | 6.5 | 2.6% | Oct 31, 2018 | The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attack... |
| CVE-2018-14653 | HIGH | 8.8 | 2.8% | Oct 31, 2018 | The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_g... |
| CVE-2018-14652 | MEDIUM | 6.5 | 2.7% | Oct 31, 2018 | The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' trans... |
| CVE-2018-16840 | CRITICAL | 9.8 | 3.3% | Oct 31, 2018 | A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy ... |
| CVE-2018-16839 | MEDIUM | 4.3 | 5.8% | Oct 31, 2018 | Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to ... |
| CVE-2018-18874 | — | — | 2.1% | Oct 31, 2018 | nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, ... |
| CVE-2018-18873 | MEDIUM | 5.5 | 1.4% | Oct 31, 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_... |
| CVE-2018-13282 | MEDIUM | 5.6 | 1.0% | Oct 31, 2018 | Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attac... |
| CVE-2018-13281 | MEDIUM | 4.3 | 1.2% | Oct 31, 2018 | Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remo... |
| CVE-2018-15327 | — | — | 1.2% | Oct 31, 2018 | In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now