2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11338 | — | — | 0.9% | Jul 31, 2018 | Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB,... |
| CVE-2018-8027 | — | — | 5.5% | Jul 31, 2018 | Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor. |
| CVE-2018-8020 | — | — | 4.2% | Jul 31, 2018 | Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced resp... |
| CVE-2018-8019 | — | — | 4.1% | Jul 31, 2018 | When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid ... |
| CVE-2018-14767 | — | — | 29.3% | Jul 31, 2018 | In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag c... |
| CVE-2018-3772 | — | — | 2.8% | Jul 30, 2018 | Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary comman... |
| CVE-2018-9066 | — | — | 2.2% | Jul 30, 2018 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstanc... |
| CVE-2018-9065 | — | — | 0.5% | Jul 30, 2018 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file ... |
| CVE-2018-9064 | — | — | 1.0% | Jul 30, 2018 | In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call ... |
| CVE-2018-14744 | — | — | 1.6% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A use-after-free can occur in _pbcM_sp_query in m... |
| CVE-2018-14743 | — | — | 1.4% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in wiretype_decode in context.c. |
| CVE-2018-14742 | — | — | 1.3% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c ... |
| CVE-2018-14741 | — | — | 1.3% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_pattern_pack in pattern.c... |
| CVE-2018-14740 | — | — | 1.3% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c ... |
| CVE-2018-14739 | — | — | 1.3% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_pattern_set_default in pa... |
| CVE-2018-14738 | — | — | 1.3% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_rmessage_message in rmess... |
| CVE-2018-14737 | — | — | 1.4% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A NULL pointer dereference can occur in pbc_wmess... |
| CVE-2018-14736 | — | — | 1.4% | Jul 30, 2018 | An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A buffer over-read can occur in pbc_wmessage_stri... |
| CVE-2018-14734 | — | — | 0.6% | Jul 29, 2018 | drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data ... |
| CVE-2018-14686 | — | — | 0.7% | Jul 28, 2018 | system/edit_book.php in XYCMS 1.7 has stored XSS via a crafted add_do.php request, related to add_book.php. |
| CVE-2018-14685 | — | — | 2.1% | Jul 28, 2018 | The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitr... |
| CVE-2018-14682 | — | — | 3.8% | Jul 28, 2018 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() mac... |
| CVE-2018-14681 | — | — | 3.8% | Jul 28, 2018 | An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header exten... |
| CVE-2018-14680 | — | — | 3.8% | Jul 28, 2018 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames. |
| CVE-2018-14679 | — | — | 3.3% | Jul 28, 2018 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now