2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-15574MEDIUM6.1An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scrip...
CVE-2018-15573HIGH8.8An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read an...
CVE-2018-15572The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not alway...
CVE-2018-15570In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.
CVE-2018-15569my little forum 2.4.12 allows CSRF for deletion of users.
CVE-2018-15568tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.
CVE-2018-15567CMSUno before 1.5.3 has XSS via the title field.
CVE-2018-15566tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter.
CVE-2018-15565An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication...
CVE-2018-15564An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any...
CVE-2018-15560HIGH7.5PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and ...
CVE-2018-15559The editor in Xiuno BBS 4.0.4 allows stored XSS.
CVE-2018-15553fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters i...
CVE-2018-15505HIGH7.5An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially...
CVE-2018-15504HIGH7.5An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP reque...
CVE-2018-15503The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker ...
CVE-2018-15501HIGH7.5In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a craf...
CVE-2018-15495/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url para...
CVE-2018-15494In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
CVE-2018-15492A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes U...
CVE-2018-15491A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9....
CVE-2018-15482Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID...
CVE-2018-14982Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is ...
CVE-2018-14981Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The ...
CVE-2018-15473MEDIUM5.3OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now