2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-12434LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka ...
CVE-2018-12356An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verifica...
CVE-2018-12432JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
CVE-2018-12431SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).
CVE-2018-6516On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-cli...
CVE-2018-12423In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
CVE-2018-12420IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
CVE-2018-8819An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated a...
CVE-2018-11690The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, cau...
CVE-2018-12421LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old pas...
CVE-2018-12114Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
CVE-2018-4848A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3),...
CVE-2018-4842A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4....
CVE-2018-4833A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE ...
CVE-2018-12418Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulne...
CVE-2018-8267A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2018-8254An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-8252An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-8251A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media ...
CVE-2018-8249A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet...
CVE-2018-8248A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2018-8247An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properl...
CVE-2018-8246An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka...
CVE-2018-8245A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local...
CVE-2018-8244An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now