2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-12693Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticat...
CVE-2018-12692TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary c...
CVE-2018-7682Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domain...
CVE-2018-12688tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.
CVE-2018-12687tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.
CVE-2018-12684Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Deni...
CVE-2018-12538In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persisten...
CVE-2018-12678Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query paramet...
CVE-2018-1000201ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used a...
CVE-2018-12636The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi...
CVE-2018-12659SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting...
CVE-2018-12657Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/maste...
CVE-2018-12656Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/member...
CVE-2018-12655Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circu...
CVE-2018-12654Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibl...
CVE-2018-12649An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force pr...
CVE-2018-12648The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer derefere...
CVE-2018-12430Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-12429. Reason: This candidate is a reservation ...
CVE-2018-12642Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
CVE-2018-12641An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion...
CVE-2018-12635CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware....
CVE-2018-12633An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_...
CVE-2018-12632Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN param...
CVE-2018-12631Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/tex...
CVE-2018-12630NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now