2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-15454HIGH8.6A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) So...
CVE-2018-18892MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name ...
CVE-2018-18891MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs to...
CVE-2018-18890MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
CVE-2018-18888An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upl...
CVE-2018-18887S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
CVE-2018-18883An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a ...
CVE-2018-15707Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could...
CVE-2018-15706WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the fil...
CVE-2018-15705WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f...
CVE-2018-14651HIGH8.8It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was inc...
CVE-2018-14661MEDIUM6.5It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red ...
CVE-2018-11759The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map ...
CVE-2018-16842MEDIUM4.4Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function ...
CVE-2018-14659MEDIUM6.5The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_...
CVE-2018-14654MEDIUM6.5The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attack...
CVE-2018-14653HIGH8.8The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_g...
CVE-2018-14652MEDIUM6.5The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' trans...
CVE-2018-16840CRITICAL9.8A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy ...
CVE-2018-16839MEDIUM4.3Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to ...
CVE-2018-18874nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, ...
CVE-2018-18873MEDIUM5.5An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_...
CVE-2018-13282MEDIUM5.6Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attac...
CVE-2018-13281MEDIUM4.3Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remo...
CVE-2018-15327In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run co...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now