2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6515 | — | — | 0.8% | Jun 11, 2018 | Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Window... |
| CVE-2018-6514 | — | — | 0.8% | Jun 11, 2018 | In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on... |
| CVE-2018-6513 | — | — | 1.1% | Jun 11, 2018 | Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x ... |
| CVE-2018-6512 | — | — | 1.9% | Jun 11, 2018 | The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. ... |
| CVE-2018-12112 | — | — | 1.3% | Jun 11, 2018 | md_build_attribute in md4c.c in md4c 0.2.6 allows remote attackers to cause a denial of service (Segmentation fault and ... |
| CVE-2018-12111 | — | — | 2.5% | Jun 11, 2018 | Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra... |
| CVE-2018-12110 | — | — | 1.1% | Jun 11, 2018 | portfolioCMS 1.0.5 has SQL Injection via the admin/portfolio.php preview parameter. |
| CVE-2018-12109 | — | — | 1.4% | Jun 11, 2018 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC<FileIO>::process function in tra... |
| CVE-2018-12108 | — | — | 1.2% | Jun 11, 2018 | An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attacke... |
| CVE-2018-12102 | — | — | 0.8% | Jun 11, 2018 | md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block. |
| CVE-2018-12100 | — | — | 1.3% | Jun 11, 2018 | Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI. |
| CVE-2018-12099 | — | — | 2.1% | Jun 11, 2018 | Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. |
| CVE-2018-12095 | — | — | 5.1% | Jun 11, 2018 | A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil... |
| CVE-2018-12094 | — | — | 1.8% | Jun 11, 2018 | Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb... |
| CVE-2018-12093 | — | — | 1.4% | Jun 11, 2018 | tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h. |
| CVE-2018-12092 | — | — | 1.6% | Jun 11, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code. |
| CVE-2018-12090 | — | — | 2.2% | Jun 11, 2018 | There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introd... |
| CVE-2018-12089 | — | — | 0.9% | Jun 11, 2018 | In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cl... |
| CVE-2018-12025 | — | — | 1.6% | Jun 11, 2018 | The transferFrom function of a smart contract implementation for FuturXE (FXE), an Ethereum ERC20 token, allows attacker... |
| CVE-2018-10360 | — | — | 3.4% | Jun 11, 2018 | The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (... |
| CVE-2018-12088 | — | — | 1.9% | Jun 10, 2018 | S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the b... |
| CVE-2018-12085 | — | — | 2.2% | Jun 9, 2018 | Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vu... |
| CVE-2018-0225 | — | — | 1.4% | Jun 8, 2018 | The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Secur... |
| CVE-2018-1281 | — | — | 1.9% | Jun 8, 2018 | The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via t... |
| CVE-2018-4253 | — | — | 0.9% | Jun 8, 2018 | An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "AMD" compon... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now