2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14828Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to...
CVE-2018-14820Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path ...
CVE-2018-14816CRITICAL9.8Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified,...
CVE-2018-14806Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrar...
CVE-2018-18626An issue was discovered in PHPYun V4.6. There is a vulnerability that can delete any file or directory via the "admin/in...
CVE-2018-18622An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username para...
CVE-2018-18608DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is u...
CVE-2018-8569A remote code execution vulnerability exists in the Yammer desktop application due to the loading of arbitrary content, ...
CVE-2018-18607An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as ...
CVE-2018-18606An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd...
CVE-2018-18605A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File D...
CVE-2018-18589MEDIUM6.3A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring softw...
CVE-2018-18603360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.s...
CVE-2018-18599Stegdetect through 2018-05-26 has an out-of-bounds write in f5_compress in the f5.c file.
CVE-2018-16837HIGH7.8Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable sit...
CVE-2018-7911Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C0...
CVE-2018-18329A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer...
CVE-2018-18328A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer...
CVE-2018-18327A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer...
CVE-2018-15367A ctl_set KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (...
CVE-2018-15366A UrlfWTPPagePtr KERedirect Use-After-Free Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer...
CVE-2018-13402Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 befor...
CVE-2018-13401The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from versi...
CVE-2018-13400Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from v...
CVE-2018-18587BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now