2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-8329An Elevation of Privilege vulnerability exists in Windows Subsystem for Linux when it fails to properly handle objects i...
CVE-2018-8320A security feature bypass vulnerability exists in DNS Global Blocklist feature, aka "Windows DNS Security Feature Bypass...
CVE-2018-8292An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in ...
CVE-2018-8265A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messa...
CVE-2018-18206In the client in Bytom before 1.0.6, checkTopicRegister in p2p/discover/net.go does not prevent negative idx values, lea...
CVE-2018-18202The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented suppor...
CVE-2018-18201qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.
CVE-2018-7633Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript cod...
CVE-2018-7632Buffer Overflow in httpd in EpiCentro E_7.3.2+ allows attackers to cause a denial of service attack remotely via a speci...
CVE-2018-7631Buffer Overflow in httpd in EpiCentro E_7.3.2+ allows attackers to execute code remotely via a specially crafted GET req...
CVE-2018-18200There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.
CVE-2018-18199Mediamanager in REDAXO before 5.6.4 has XSS.
CVE-2018-18198The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is ...
CVE-2018-17963CRITICAL9.8qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause ...
CVE-2018-17962Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
CVE-2018-17958HIGH7.5Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
CVE-2018-17866Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User...
CVE-2018-11796In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParser...
CVE-2018-17859An issue was discovered in Joomla! before 3.8.13. Inadequate checks in com_contact could allow mail submission in disabl...
CVE-2018-17858An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the bac...
CVE-2018-17857An issue was discovered in Joomla! before 3.8.13. Inadequate checks on the tags search fields can lead to an access leve...
CVE-2018-17856An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default A...
CVE-2018-17855An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can appr...
CVE-2018-10614An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes speciall...
CVE-2018-10610An out-of-bounds vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processe...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now