2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18586chmextract.c in the chmextract sample program, as distributed with libmspack before 0.8alpha, does not protect against a...
CVE-2018-18585MEDIUM4.3chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second ...
CVE-2018-18584MEDIUM6.5In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small...
CVE-2018-18583An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c d...
CVE-2018-18582An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c d...
CVE-2018-18581An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer over-read in internalPrintf in miniz/lupn...
CVE-2018-18579Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.
CVE-2018-18578DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.
CVE-2018-13115Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the came...
CVE-2018-13114Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute...
CVE-2018-15704Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attac...
CVE-2018-15703Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote u...
CVE-2018-12246Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability...
CVE-2018-18559HIGH8.1In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt ...
CVE-2018-18557LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3...
CVE-2018-1850HIGH8.8IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations wh...
CVE-2018-18553Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.
CVE-2018-18550ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user.
CVE-2018-18546ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder functi...
CVE-2018-18545MEDIUM6.1Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.
CVE-2018-18544There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function Proce...
CVE-2018-18541In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connectio...
CVE-2018-18540TeaKKi 2.7 allows XSS via a crafted onerror attribute for a picture's URL.
CVE-2018-18438Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size ...
CVE-2018-18428TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now