2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-3914HIGH7.8An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT...
CVE-2018-3913MEDIUM6.7An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT...
CVE-2018-3906HIGH8.2An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTT...
CVE-2018-3894HIGH8.8An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa...
CVE-2018-16786DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.
CVE-2018-16784DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring...
CVE-2018-11241An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary f...
CVE-2018-11240An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' fea...
CVE-2018-3877CRITICAL9.9An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-3876HIGH8.8An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-3874CRITICAL9.9An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-3873CRITICAL9.9An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-8023Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Ap...
CVE-2018-1711HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ...
CVE-2018-1710HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffe...
CVE-2018-1685IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in ...
CVE-2018-14645HIGH7.5A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read acc...
CVE-2018-14643CRITICAL9.8An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can u...
CVE-2018-17302Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
CVE-2018-17301Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search p...
CVE-2018-17300MEDIUM4.8Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section na...
CVE-2018-17298An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its...
CVE-2018-17297The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via dire...
CVE-2018-17294The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's l...
CVE-2018-17293An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether the...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now