2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11262In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while ...
CVE-2018-10930MEDIUM6.5A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw...
CVE-2018-10929HIGH8.8A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw...
CVE-2018-10928HIGH8.8A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to...
CVE-2018-10927HIGH8.1A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw...
CVE-2018-10926HIGH8.8A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use ...
CVE-2018-10924MEDIUM5.3It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use t...
CVE-2018-10923HIGH8.1It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node...
CVE-2018-10914MEDIUM6.5It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash whi...
CVE-2018-10913MEDIUM6.5An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via ...
CVE-2018-10911HIGH7.5A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacke...
CVE-2018-10907HIGH8.8It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc...
CVE-2018-10904HIGH8.8It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribu...
CVE-2018-0675AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.
CVE-2018-0674AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors.
CVE-2018-0672Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitr...
CVE-2018-0664A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unsp...
CVE-2018-0656Untrusted search path vulnerability in The installer of Digital Paper App version 1.4.0.16050 and earlier allows an atta...
CVE-2018-0646Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecifie...
CVE-2018-14627MEDIUM5.3The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required...
CVE-2018-16458An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication o...
CVE-2018-16450CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
CVE-2018-16449OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Arti...
CVE-2018-16448Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.ph...
CVE-2018-16447Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now