2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11491 | — | — | 6.7% | Jul 25, 2018 | ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution. |
| CVE-2018-14596 | — | — | 1.3% | Jul 25, 2018 | wancms 1.0 through 5.0 allows remote attackers to cause a denial of service (resource consumption) via a checkcode (aka ... |
| CVE-2018-11047 | — | — | 1.1% | Jul 24, 2018 | Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.... |
| CVE-2018-11044 | — | — | 0.7% | Jul 24, 2018 | Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and... |
| CVE-2018-10628 | — | — | 5.4% | Jul 24, 2018 | AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthentic... |
| CVE-2018-10632 | — | — | 1.7% | Jul 24, 2018 | In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicio... |
| CVE-2018-14590 | — | — | 1.4% | Jul 24, 2018 | An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Processor::ProcessFragments in Core/Ap4Process... |
| CVE-2018-14589 | — | — | 1.5% | Jul 24, 2018 | An issue has been discovered in Bento4 1.5.1-624. AP4_Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a he... |
| CVE-2018-14588 | — | — | 1.4% | Jul 24, 2018 | An issue has been discovered in Bento4 1.5.1-624. A NULL pointer dereference can occur in AP4_DataBuffer::SetData in Cor... |
| CVE-2018-14587 | — | — | 1.5% | Jul 24, 2018 | An issue has been discovered in Bento4 1.5.1-624. AP4_MemoryByteStream::WritePartial in Core/Ap4ByteStream.cpp has a buf... |
| CVE-2018-14586 | — | — | 1.5% | Jul 24, 2018 | An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Mpeg2TsAudioSampleStream::WriteSample in Core/... |
| CVE-2018-14585 | — | — | 1.5% | Jul 24, 2018 | An issue has been discovered in Bento4 1.5.1-624. AP4_BytesToUInt16BE in Core/Ap4Utils.h has a heap-based buffer over-re... |
| CVE-2018-14584 | — | — | 1.6% | Jul 24, 2018 | An issue has been discovered in Bento4 1.5.1-624. AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp has a heap-based buffer o... |
| CVE-2018-14583 | — | — | 0.5% | Jul 24, 2018 | xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account. |
| CVE-2018-14582 | — | — | 0.5% | Jul 24, 2018 | index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account. |
| CVE-2018-5386 | — | — | 4.6% | Jul 24, 2018 | Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading t... |
| CVE-2018-5385 | — | — | 4.2% | Jul 24, 2018 | Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can l... |
| CVE-2018-5384 | — | — | 4.4% | Jul 24, 2018 | Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection... |
| CVE-2018-14579 | — | — | 1.6% | Jul 24, 2018 | GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to ... |
| CVE-2018-13386 | — | — | 1.6% | Jul 24, 2018 | There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An atta... |
| CVE-2018-13385 | — | — | 2.2% | Jul 24, 2018 | There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attack... |
| CVE-2018-10608 | — | — | 7.8% | Jul 24, 2018 | SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects... |
| CVE-2018-10600 | — | — | 2.5% | Jul 24, 2018 | SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may ... |
| CVE-2018-14573 | — | — | 6.4% | Jul 23, 2018 | A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage b... |
| CVE-2018-8031 | — | — | 2.0% | Jul 23, 2018 | The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now