2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11222 | — | — | 5.6% | Jun 16, 2018 | Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /p... |
| CVE-2018-11221 | — | — | 5.0% | Jun 16, 2018 | Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitra... |
| CVE-2018-5863 | — | — | 0.2% | Jun 15, 2018 | If userspace provides a too-large WPA RSN IE length in wlan_hdd_cfg80211_set_ie(), a buffer overflow occurs in all Andro... |
| CVE-2018-5860 | — | — | 0.1% | Jun 15, 2018 | In the MDSS driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux ke... |
| CVE-2018-12498 | — | — | 1.5% | Jun 15, 2018 | spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.ph... |
| CVE-2018-12495 | — | — | 1.8% | Jun 15, 2018 | The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of s... |
| CVE-2018-12494 | — | — | 1.7% | Jun 15, 2018 | An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerabi... |
| CVE-2018-12493 | — | — | 1.7% | Jun 15, 2018 | An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerabi... |
| CVE-2018-12492 | — | — | 0.9% | Jun 15, 2018 | PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php. |
| CVE-2018-12491 | — | — | 1.7% | Jun 15, 2018 | PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php... |
| CVE-2018-12481 | — | — | 1.1% | Jun 15, 2018 | The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonst... |
| CVE-2018-12422 | — | — | 1.8% | Jun 15, 2018 | addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow a... |
| CVE-2018-12035 | — | — | 1.2% | Jun 15, 2018 | In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability i... |
| CVE-2018-12034 | — | — | 1.2% | Jun 15, 2018 | In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in... |
| CVE-2018-12030 | — | — | 0.7% | Jun 15, 2018 | Chevereto Free before 1.0.13 has XSS. |
| CVE-2018-5857 | — | — | 0.2% | Jun 15, 2018 | In the WCD CPE codec, a Use After Free condition can occur in all Android releases(Android for MSM, Firefox OS for MSM, ... |
| CVE-2018-5854 | — | — | 0.2% | Jun 15, 2018 | A stack-based buffer overflow can occur in fastboot from all Android releases(Android for MSM, Firefox OS for MSM, QRD A... |
| CVE-2018-12460 | — | — | 1.1% | Jun 15, 2018 | libavcodec in FFmpeg 4.0 may trigger a NULL pointer dereference if the studio profile is incorrectly detected while conv... |
| CVE-2018-12459 | — | — | 1.1% | Jun 15, 2018 | An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c in FF... |
| CVE-2018-12457 | — | — | 1.9% | Jun 15, 2018 | expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header. |
| CVE-2018-12447 | — | — | 3.8% | Jun 15, 2018 | The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integ... |
| CVE-2018-12440 | — | — | 0.1% | Jun 15, 2018 | BoringSSL through 2018-06-14 allows a memory-cache side-channel attack on DSA signatures, aka the Return Of the Hidden N... |
| CVE-2018-12439 | — | — | 0.3% | Jun 15, 2018 | MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden... |
| CVE-2018-12436 | — | — | 0.4% | Jun 15, 2018 | wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka th... |
| CVE-2018-12435 | — | — | 0.5% | Jun 15, 2018 | Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now