2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18586 | — | — | 3.3% | Oct 23, 2018 | chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against a... |
| CVE-2018-18585 | MEDIUM | 4.3 | 3.1% | Oct 23, 2018 | chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second ... |
| CVE-2018-18584 | MEDIUM | 6.5 | 3.1% | Oct 23, 2018 | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small... |
| CVE-2018-18583 | — | — | 1.4% | Oct 22, 2018 | An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c d... |
| CVE-2018-18582 | — | — | 1.4% | Oct 22, 2018 | An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c d... |
| CVE-2018-18581 | — | — | 1.3% | Oct 22, 2018 | An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer over-read in internalPrintf in miniz/lupn... |
| CVE-2018-18579 | — | — | 0.7% | Oct 22, 2018 | Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter. |
| CVE-2018-18578 | — | — | 0.7% | Oct 22, 2018 | DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter. |
| CVE-2018-13115 | — | — | 1.0% | Oct 22, 2018 | Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the came... |
| CVE-2018-13114 | — | — | 1.9% | Oct 22, 2018 | Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute... |
| CVE-2018-15704 | — | — | 21.5% | Oct 22, 2018 | Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attac... |
| CVE-2018-15703 | — | — | 0.9% | Oct 22, 2018 | Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote u... |
| CVE-2018-12246 | — | — | 1.0% | Oct 22, 2018 | Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability... |
| CVE-2018-18559 | HIGH | 8.1 | 2.6% | Oct 22, 2018 | In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt ... |
| CVE-2018-18557 | — | — | 15.0% | Oct 22, 2018 | LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3... |
| CVE-2018-1850 | HIGH | 8.8 | 2.2% | Oct 22, 2018 | IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations wh... |
| CVE-2018-18553 | — | — | 0.9% | Oct 22, 2018 | Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page. |
| CVE-2018-18550 | — | — | 0.9% | Oct 21, 2018 | ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user. |
| CVE-2018-18546 | — | — | 1.7% | Oct 21, 2018 | ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder functi... |
| CVE-2018-18545 | MEDIUM | 6.1 | 0.8% | Oct 21, 2018 | Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter. |
| CVE-2018-18544 | — | — | 2.0% | Oct 21, 2018 | There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function Proce... |
| CVE-2018-18541 | — | — | 3.0% | Oct 20, 2018 | In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connectio... |
| CVE-2018-18540 | — | — | 0.8% | Oct 20, 2018 | TeaKKi 2.7 allows XSS via a crafted onerror attribute for a picture's URL. |
| CVE-2018-18438 | — | — | 0.4% | Oct 19, 2018 | Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size ... |
| CVE-2018-18428 | — | — | 11.5% | Oct 19, 2018 | TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now