2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-6515Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Window...
CVE-2018-6514In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on...
CVE-2018-6513Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x ...
CVE-2018-6512The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. ...
CVE-2018-12112md_build_attribute in md4c.c in md4c 0.2.6 allows remote attackers to cause a denial of service (Segmentation fault and ...
CVE-2018-12111Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra...
CVE-2018-12110portfolioCMS 1.0.5 has SQL Injection via the admin/portfolio.php preview parameter.
CVE-2018-12109An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC<FileIO>::process function in tra...
CVE-2018-12108An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attacke...
CVE-2018-12102md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.
CVE-2018-12100Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.
CVE-2018-12099Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
CVE-2018-12095A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil...
CVE-2018-12094Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb...
CVE-2018-12093tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.
CVE-2018-12092tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
CVE-2018-12090There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introd...
CVE-2018-12089In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cl...
CVE-2018-12025The transferFrom function of a smart contract implementation for FuturXE (FXE), an Ethereum ERC20 token, allows attacker...
CVE-2018-10360The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (...
CVE-2018-12088S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the b...
CVE-2018-12085Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vu...
CVE-2018-0225The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Secur...
CVE-2018-1281The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via t...
CVE-2018-4253An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "AMD" compon...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now