2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-4159An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Graphics Dr...
CVE-2018-4141An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Intel Graph...
CVE-2018-12066BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon ...
CVE-2018-10506A out-of-bounds read information disclosure vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local ...
CVE-2018-10505A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attac...
CVE-2018-10359A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attac...
CVE-2018-10358A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attac...
CVE-2018-12065A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to...
CVE-2018-12064tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.
CVE-2018-11409Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json ...
CVE-2018-10088Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE...
CVE-2018-12055Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph...
CVE-2018-12054Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol...
CVE-2018-12053Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p...
CVE-2018-12052SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
CVE-2018-12051Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in ...
CVE-2018-9246The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes...
CVE-2018-9182Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
CVE-2018-9177Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
CVE-2018-12049A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.c...
CVE-2018-12048A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi ...
CVE-2018-12047xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by ...
CVE-2018-12046DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=...
CVE-2018-12045DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmd...
CVE-2018-12041An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny ser...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now