2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10404 | — | — | 0.9% | Jun 13, 2018 | An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously craf... |
| CVE-2018-10403 | — | — | 0.8% | Jun 13, 2018 | An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade thir... |
| CVE-2018-5488 | — | — | 4.0% | Jun 13, 2018 | NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30... |
| CVE-2018-12339 | — | — | 0.5% | Jun 13, 2018 | ArticleCMS through 2017-02-19 has XSS via an "add an article" action. |
| CVE-2018-7559 | — | — | 1.6% | Jun 13, 2018 | An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET L... |
| CVE-2018-10363 | — | — | 1.4% | Jun 13, 2018 | An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multi... |
| CVE-2018-5242 | — | — | 0.4% | Jun 13, 2018 | Norton App Lock prior to version 1.3.0.329 can be susceptible to a bypass exploit. In this type of circumstance, the exp... |
| CVE-2018-12323 | — | — | 0.4% | Jun 13, 2018 | An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin a... |
| CVE-2018-12322 | — | — | 0.8% | Jun 13, 2018 | There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM bina... |
| CVE-2018-12321 | — | — | 1.0% | Jun 13, 2018 | There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java bi... |
| CVE-2018-12320 | — | — | 1.0% | Jun 13, 2018 | There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file. |
| CVE-2018-11688 | — | — | 2.4% | Jun 13, 2018 | Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-suppl... |
| CVE-2018-11408 | — | — | 1.1% | Jun 13, 2018 | The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3... |
| CVE-2018-11407 | — | — | 2.3% | Jun 13, 2018 | An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, a... |
| CVE-2018-11406 | — | — | 0.8% | Jun 13, 2018 | An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.... |
| CVE-2018-11386 | — | — | 1.6% | Jun 13, 2018 | An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x befor... |
| CVE-2018-11385 | — | — | 2.0% | Jun 13, 2018 | An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.... |
| CVE-2018-3759 | — | — | 0.7% | Jun 13, 2018 | private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to ... |
| CVE-2018-12292 | — | — | 9.2% | Jun 13, 2018 | A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3. |
| CVE-2018-12291 | — | — | 1.8% | Jun 13, 2018 | The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the g... |
| CVE-2018-12290 | — | — | 0.7% | Jun 13, 2018 | The Yii2-StateMachine extension v2.x.x for Yii2 has XSS. |
| CVE-2018-12273 | — | — | 0.9% | Jun 13, 2018 | The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter. |
| CVE-2018-12272 | — | — | 0.9% | Jun 13, 2018 | xowl/request.php in Ximdex 4.0 has XSS via the content parameter. |
| CVE-2018-12268 | — | — | 2.6% | Jun 13, 2018 | acccheck.pl in acccheck 0.2.1 allows Command Injection via shell metacharacters in a username or password file, as demon... |
| CVE-2018-12266 | — | — | 0.7% | Jun 13, 2018 | system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now