2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17101 | — | — | 3.2% | Sep 16, 2018 | An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2... |
| CVE-2018-17100 | — | — | 2.5% | Sep 16, 2018 | An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause ... |
| CVE-2018-17098 | — | — | 2.8% | Sep 16, 2018 | The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of serv... |
| CVE-2018-17097 | — | — | 2.8% | Sep 16, 2018 | The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of serv... |
| CVE-2018-17096 | — | — | 2.3% | Sep 16, 2018 | The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cau... |
| CVE-2018-17095 | HIGH | 8.8 | 4.7% | Sep 16, 2018 | An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3... |
| CVE-2018-17094 | — | — | — | Sep 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11124. Reason: This candidate is a duplicate of ... |
| CVE-2018-17093 | — | — | — | Sep 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11125. Reason: This candidate is a duplicate of ... |
| CVE-2018-17092 | — | — | 0.6% | Sep 16, 2018 | An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be explo... |
| CVE-2018-17091 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via ... |
| CVE-2018-17090 | — | — | 0.5% | Sep 16, 2018 | An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulne... |
| CVE-2018-17088 | — | — | 1.6% | Sep 16, 2018 | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service... |
| CVE-2018-17086 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 t... |
| CVE-2018-17085 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeS... |
| CVE-2018-17062 | — | — | 0.7% | Sep 16, 2018 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isuni... |
| CVE-2018-17082 | — | — | 4.1% | Sep 16, 2018 | The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS... |
| CVE-2018-17077 | — | — | 0.8% | Sep 16, 2018 | An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be ... |
| CVE-2018-17076 | — | — | 1.5% | Sep 16, 2018 | GPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or po... |
| CVE-2018-17075 | HIGH | 7.5 | 2.8% | Sep 16, 2018 | The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: ... |
| CVE-2018-17074 | — | — | 1.2% | Sep 16, 2018 | The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. |
| CVE-2018-17073 | — | — | 1.2% | Sep 16, 2018 | wernsey/bitmap before 2018-08-18 allows a NULL pointer dereference via a 4-bit image. |
| CVE-2018-17072 | — | — | 1.6% | Sep 16, 2018 | JSON++ through 2016-06-15 has a buffer over-read in yyparse() in json.y. |
| CVE-2018-16554 | — | — | 1.8% | Sep 16, 2018 | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service... |
| CVE-2018-17070 | — | — | 0.5% | Sep 15, 2018 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2F... |
| CVE-2018-17069 | — | — | 0.5% | Sep 15, 2018 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now