2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12434 | — | — | 0.3% | Jun 15, 2018 | LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka ... |
| CVE-2018-12356 | — | — | 4.6% | Jun 15, 2018 | An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verifica... |
| CVE-2018-12432 | — | — | 0.7% | Jun 14, 2018 | JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI. |
| CVE-2018-12431 | — | — | 0.5% | Jun 14, 2018 | SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page). |
| CVE-2018-6516 | — | — | 0.8% | Jun 14, 2018 | On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-cli... |
| CVE-2018-12423 | — | — | 1.8% | Jun 14, 2018 | In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force. |
| CVE-2018-12420 | — | — | 1.0% | Jun 14, 2018 | IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request. |
| CVE-2018-8819 | — | — | 3.1% | Jun 14, 2018 | An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated a... |
| CVE-2018-11690 | — | — | 33.5% | Jun 14, 2018 | The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, cau... |
| CVE-2018-12421 | — | — | 2.8% | Jun 14, 2018 | LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old pas... |
| CVE-2018-12114 | — | — | 3.0% | Jun 14, 2018 | Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. |
| CVE-2018-4848 | — | — | 1.0% | Jun 14, 2018 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3),... |
| CVE-2018-4842 | — | — | 0.8% | Jun 14, 2018 | A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.... |
| CVE-2018-4833 | — | — | 1.0% | Jun 14, 2018 | A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE ... |
| CVE-2018-12418 | — | — | 1.2% | Jun 14, 2018 | Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulne... |
| CVE-2018-8267 | — | — | 15.8% | Jun 14, 2018 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2018-8254 | — | — | 2.5% | Jun 14, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-8252 | — | — | 2.5% | Jun 14, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-8251 | — | — | 7.4% | Jun 14, 2018 | A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media ... |
| CVE-2018-8249 | — | — | 13.9% | Jun 14, 2018 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2018-8248 | — | — | 20.1% | Jun 14, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-8247 | — | — | 3.2% | Jun 14, 2018 | An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properl... |
| CVE-2018-8246 | — | — | 17.4% | Jun 14, 2018 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka... |
| CVE-2018-8245 | — | — | 15.4% | Jun 14, 2018 | A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local... |
| CVE-2018-8244 | — | — | 4.9% | Jun 14, 2018 | An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now