2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14373 | — | — | — | Jul 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-14347 | — | — | 1.7% | Jul 17, 2018 | GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c). |
| CVE-2018-14346 | — | — | 2.1% | Jul 17, 2018 | GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c). |
| CVE-2018-14345 | — | — | 1.0% | Jul 17, 2018 | An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for us... |
| CVE-2018-13862 | — | — | 50.6% | Jul 17, 2018 | Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker... |
| CVE-2018-13861 | — | — | 2.3% | Jul 17, 2018 | Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allows unauthorized remote attacke... |
| CVE-2018-13860 | — | — | 1.4% | Jul 17, 2018 | MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18 allo... |
| CVE-2018-13859 | — | — | 17.9% | Jul 17, 2018 | MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all... |
| CVE-2018-13858 | — | — | 2.3% | Jul 17, 2018 | MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional allows unauthorized remote attackers to ... |
| CVE-2018-14338 | — | — | 1.4% | Jul 17, 2018 | samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple ... |
| CVE-2018-13864 | — | — | 3.4% | Jul 17, 2018 | A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fix... |
| CVE-2018-14334 | — | — | 1.7% | Jul 17, 2018 | manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file exten... |
| CVE-2018-14333 | — | — | 2.6% | Jul 17, 2018 | TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] a... |
| CVE-2018-14331 | — | — | 0.5% | Jul 17, 2018 | An issue was discovered in XiaoCms X1 v20140305. There is a CSRF vulnerability to change the administrator account passw... |
| CVE-2018-0710 | — | — | 14.2% | Jul 17, 2018 | Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe... |
| CVE-2018-0709 | — | — | 13.6% | Jul 17, 2018 | Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth... |
| CVE-2018-0708 | — | — | 26.3% | Jul 17, 2018 | Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo... |
| CVE-2018-0707 | — | — | 59.2% | Jul 17, 2018 | Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could... |
| CVE-2018-0706 | — | — | 48.7% | Jul 17, 2018 | Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate... |
| CVE-2018-13832 | — | — | 2.0% | Jul 16, 2018 | Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu... |
| CVE-2018-10886 | — | — | — | Jul 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate is not about any specific ... |
| CVE-2018-14326 | — | — | 1.9% | Jul 16, 2018 | In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom... |
| CVE-2018-14325 | — | — | 2.0% | Jul 16, 2018 | In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp. |
| CVE-2018-14324 | — | — | 4.4% | Jul 16, 2018 | The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin ... |
| CVE-2018-5239 | — | — | 0.4% | Jul 16, 2018 | Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit. In this type of circumstance, the exploit ca... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now