2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18706 | — | — | 1.1% | Oct 29, 2018 | An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19... |
| CVE-2018-18705 | — | — | 2.0% | Oct 29, 2018 | PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user paramete... |
| CVE-2018-18704 | — | — | 1.6% | Oct 29, 2018 | PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter. |
| CVE-2018-18703 | — | — | 4.1% | Oct 29, 2018 | PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different ... |
| CVE-2018-18702 | — | — | 1.5% | Oct 29, 2018 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile con... |
| CVE-2018-18701 | — | — | 1.7% | Oct 29, 2018 | An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consump... |
| CVE-2018-18700 | — | — | 1.7% | Oct 29, 2018 | An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consump... |
| CVE-2018-18699 | — | — | 1.4% | Oct 29, 2018 | An issue was discovered in GoPro gpmf-parser 1.2.1. There is an out-of-bounds write in OpenMP4Source in GPMF_mp4reader.c... |
| CVE-2018-18694 | — | — | 0.9% | Oct 29, 2018 | admin/index.php?id=filesmanager in Monstra CMS 3.0.4 allows remote authenticated administrators to trigger stored XSS vi... |
| CVE-2018-18690 | — | — | 0.7% | Oct 26, 2018 | In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem... |
| CVE-2018-6559 | — | — | 0.5% | Oct 26, 2018 | The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which the... |
| CVE-2018-4022 | HIGH | 7.8 | 1.5% | Oct 26, 2018 | A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A sp... |
| CVE-2018-18662 | — | — | 1.6% | Oct 26, 2018 | There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool. |
| CVE-2018-18661 | — | — | 2.9% | Oct 26, 2018 | An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_... |
| CVE-2018-18660 | MEDIUM | 6.1 | 0.9% | Oct 26, 2018 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Refle... |
| CVE-2018-18659 | — | — | 1.8% | Oct 26, 2018 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unaut... |
| CVE-2018-18658 | — | — | 1.3% | Oct 26, 2018 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unaut... |
| CVE-2018-18657 | — | — | 1.3% | Oct 26, 2018 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unaut... |
| CVE-2018-15688 | HIGH | 8.8 | 1.7% | Oct 26, 2018 | A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory ... |
| CVE-2018-15687 | HIGH | 7 | 1.1% | Oct 26, 2018 | A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary... |
| CVE-2018-15686 | HIGH | 7.8 | 2.3% | Oct 26, 2018 | A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution ... |
| CVE-2018-5914 | — | — | 0.2% | Oct 26, 2018 | Improper input validation in TZ led to array out of bound in TZ function while accessing the peripheral details using th... |
| CVE-2018-5866 | — | — | 0.2% | Oct 26, 2018 | While processing logs, data is copied into a buffer pointed to by an untrusted pointer in Snapdragon Mobile, Snapdragon ... |
| CVE-2018-3588 | — | — | 0.2% | Oct 26, 2018 | There is improper access control of the SSC and GPU mapped regions which lead to inject code from HLOS in Snapdragon Aut... |
| CVE-2018-11951 | — | — | 0.2% | Oct 26, 2018 | Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapd... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now