2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12693 | — | — | 15.8% | Jun 23, 2018 | Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticat... |
| CVE-2018-12692 | — | — | 29.1% | Jun 23, 2018 | TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary c... |
| CVE-2018-7682 | — | — | 0.8% | Jun 22, 2018 | Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domain... |
| CVE-2018-12688 | — | — | 1.6% | Jun 22, 2018 | tinyexr 0.9.5 has a segmentation fault in the wav2Decode function. |
| CVE-2018-12687 | — | — | 1.4% | Jun 22, 2018 | tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h. |
| CVE-2018-12684 | — | — | 1.1% | Jun 22, 2018 | Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Deni... |
| CVE-2018-12538 | — | — | 2.7% | Jun 22, 2018 | In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persisten... |
| CVE-2018-12678 | — | — | 2.3% | Jun 22, 2018 | Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query paramet... |
| CVE-2018-1000201 | — | — | 1.4% | Jun 22, 2018 | ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used a... |
| CVE-2018-12636 | — | — | 30.1% | Jun 22, 2018 | The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi... |
| CVE-2018-12659 | — | — | 0.8% | Jun 22, 2018 | SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting... |
| CVE-2018-12657 | — | — | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/maste... |
| CVE-2018-12656 | — | — | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/member... |
| CVE-2018-12655 | — | — | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circu... |
| CVE-2018-12654 | — | — | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibl... |
| CVE-2018-12649 | — | — | 1.5% | Jun 22, 2018 | An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force pr... |
| CVE-2018-12648 | — | — | 2.3% | Jun 22, 2018 | The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer derefere... |
| CVE-2018-12430 | — | — | — | Jun 22, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-12429. Reason: This candidate is a reservation ... |
| CVE-2018-12642 | — | — | 1.4% | Jun 22, 2018 | Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user. |
| CVE-2018-12641 | — | — | 2.1% | Jun 22, 2018 | An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion... |
| CVE-2018-12635 | — | — | 0.9% | Jun 22, 2018 | CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.... |
| CVE-2018-12633 | — | — | 0.3% | Jun 22, 2018 | An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_... |
| CVE-2018-12632 | — | — | 1.4% | Jun 21, 2018 | Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN param... |
| CVE-2018-12631 | — | — | 3.3% | Jun 21, 2018 | Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/tex... |
| CVE-2018-12630 | — | — | 1.6% | Jun 21, 2018 | NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now