2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11262 | — | — | 0.2% | Sep 4, 2018 | In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while ... |
| CVE-2018-10930 | MEDIUM | 6.5 | 2.1% | Sep 4, 2018 | A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw... |
| CVE-2018-10929 | HIGH | 8.8 | 3.3% | Sep 4, 2018 | A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw... |
| CVE-2018-10928 | HIGH | 8.8 | 2.7% | Sep 4, 2018 | A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to... |
| CVE-2018-10927 | HIGH | 8.1 | 2.8% | Sep 4, 2018 | A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw... |
| CVE-2018-10926 | HIGH | 8.8 | 2.6% | Sep 4, 2018 | A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use ... |
| CVE-2018-10924 | MEDIUM | 5.3 | 1.9% | Sep 4, 2018 | It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use t... |
| CVE-2018-10923 | HIGH | 8.1 | 1.7% | Sep 4, 2018 | It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node... |
| CVE-2018-10914 | MEDIUM | 6.5 | 2.4% | Sep 4, 2018 | It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash whi... |
| CVE-2018-10913 | MEDIUM | 6.5 | 2.1% | Sep 4, 2018 | An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via ... |
| CVE-2018-10911 | HIGH | 7.5 | 3.1% | Sep 4, 2018 | A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacke... |
| CVE-2018-10907 | HIGH | 8.8 | 3.4% | Sep 4, 2018 | It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc... |
| CVE-2018-10904 | HIGH | 8.8 | 3.0% | Sep 4, 2018 | It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribu... |
| CVE-2018-0675 | — | — | 1.4% | Sep 4, 2018 | AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors. |
| CVE-2018-0674 | — | — | 1.4% | Sep 4, 2018 | AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors. |
| CVE-2018-0672 | — | — | 0.8% | Sep 4, 2018 | Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitr... |
| CVE-2018-0664 | — | — | 1.7% | Sep 4, 2018 | A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unsp... |
| CVE-2018-0656 | — | — | 1.3% | Sep 4, 2018 | Untrusted search path vulnerability in The installer of Digital Paper App version 1.4.0.16050 and earlier allows an atta... |
| CVE-2018-0646 | — | — | 2.0% | Sep 4, 2018 | Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecifie... |
| CVE-2018-14627 | MEDIUM | 5.3 | 1.1% | Sep 4, 2018 | The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required... |
| CVE-2018-16458 | — | — | 0.4% | Sep 4, 2018 | An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication o... |
| CVE-2018-16450 | — | — | 0.7% | Sep 4, 2018 | CraftedWeb through 2013-09-24 has reflected XSS via the p parameter. |
| CVE-2018-16449 | — | — | 0.6% | Sep 4, 2018 | OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Arti... |
| CVE-2018-16448 | — | — | 0.5% | Sep 4, 2018 | Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.ph... |
| CVE-2018-16447 | — | — | 0.7% | Sep 4, 2018 | Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now