2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18706An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19...
CVE-2018-18705PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user paramete...
CVE-2018-18704PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.
CVE-2018-18703PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different ...
CVE-2018-18702spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile con...
CVE-2018-18701An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consump...
CVE-2018-18700An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consump...
CVE-2018-18699An issue was discovered in GoPro gpmf-parser 1.2.1. There is an out-of-bounds write in OpenMP4Source in GPMF_mp4reader.c...
CVE-2018-18694admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS vi...
CVE-2018-18690In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem...
CVE-2018-6559The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which the...
CVE-2018-4022HIGH7.8A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A sp...
CVE-2018-18662There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.
CVE-2018-18661An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_...
CVE-2018-18660MEDIUM6.1An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Refle...
CVE-2018-18659An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unaut...
CVE-2018-18658An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unaut...
CVE-2018-18657An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unaut...
CVE-2018-15688HIGH8.8A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory ...
CVE-2018-15687HIGH7A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary...
CVE-2018-15686HIGH7.8A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution ...
CVE-2018-5914Improper input validation in TZ led to array out of bound in TZ function while accessing the peripheral details using th...
CVE-2018-5866While processing logs, data is copied into a buffer pointed to by an untrusted pointer in Snapdragon Mobile, Snapdragon ...
CVE-2018-3588There is improper access control of the SSC and GPU mapped regions which lead to inject code from HLOS in Snapdragon Aut...
CVE-2018-11951Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapd...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now