2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16464 | — | — | 0.9% | Oct 30, 2018 | A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link sha... |
| CVE-2018-16463 | — | — | 0.5% | Oct 30, 2018 | A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacke... |
| CVE-2018-16462 | CRITICAL | 10 | 7.0% | Oct 30, 2018 | A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shel... |
| CVE-2018-16461 | — | — | 3.9% | Oct 30, 2018 | A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via ... |
| CVE-2018-18281 | — | — | 1.1% | Oct 30, 2018 | Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall s... |
| CVE-2018-17783 | — | — | 0.7% | Oct 30, 2018 | A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 throu... |
| CVE-2018-17782 | — | — | 0.7% | Oct 30, 2018 | A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through... |
| CVE-2018-14558 | CRITICAL | 9.8 | 8.7% | Oct 30, 2018 | An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware throu... |
| CVE-2018-10712 | — | — | 1.3% | Oct 30, 2018 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str... |
| CVE-2018-10711 | — | — | 1.5% | Oct 30, 2018 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str... |
| CVE-2018-10710 | — | — | 1.0% | Oct 30, 2018 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str... |
| CVE-2018-10709 | — | — | 1.2% | Oct 30, 2018 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str... |
| CVE-2018-10532 | — | — | 2.4% | Oct 30, 2018 | An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discover... |
| CVE-2018-0734 | MEDIUM | 5.9 | 12.2% | Oct 30, 2018 | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could u... |
| CVE-2018-18842 | — | — | 0.8% | Oct 30, 2018 | CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to e... |
| CVE-2018-18841 | — | — | 0.5% | Oct 30, 2018 | XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter. |
| CVE-2018-18840 | — | — | 0.6% | Oct 30, 2018 | XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter. |
| CVE-2018-18835 | — | — | 1.6% | Oct 30, 2018 | upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via... |
| CVE-2018-18834 | — | — | 2.1% | Oct 30, 2018 | An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/a... |
| CVE-2018-18832 | — | — | 1.3% | Oct 30, 2018 | admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp. |
| CVE-2018-18831 | — | — | 1.5% | Oct 30, 2018 | An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file... |
| CVE-2018-18830 | — | — | 1.2% | Oct 30, 2018 | An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does ... |
| CVE-2018-18829 | — | — | 0.9% | Oct 30, 2018 | There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers ... |
| CVE-2018-18828 | — | — | 0.9% | Oct 30, 2018 | There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers... |
| CVE-2018-18827 | — | — | 0.9% | Oct 30, 2018 | There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cau... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now