2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-15839CRITICAL9.8D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
CVE-2018-15571The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.
CVE-2018-15529A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authentic...
CVE-2018-13395Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 be...
CVE-2018-13391The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from v...
CVE-2018-1705MEDIUM6.5IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclo...
CVE-2018-15919MEDIUM5.3Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existenc...
CVE-2018-15911In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memor...
CVE-2018-3690Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3693. Reason: This issue was MERGED into CVE-201...
CVE-2018-15910In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the ...
CVE-2018-15909In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers ab...
CVE-2018-15908In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfi...
CVE-2018-3927MEDIUM6.8An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung Sma...
CVE-2018-3918HIGH7.5An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20...
CVE-2018-3904CRITICAL9.9An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsun...
CVE-2018-3893HIGH8.8An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa...
CVE-2018-15904A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8,...
CVE-2018-15887Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allo...
CVE-2018-15810Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize f...
CVE-2018-1644LOW3.1IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 -...
CVE-2018-15699ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in t...
CVE-2018-15698ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file sy...
CVE-2018-15697ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by ...
CVE-2018-15696ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts ...
CVE-2018-15695ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now