2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1332 | — | — | 1.5% | Jun 5, 2018 | Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that cou... |
| CVE-2018-7943 | — | — | 1.2% | Jun 5, 2018 | There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass ... |
| CVE-2018-10966 | — | — | 1.6% | Jun 5, 2018 | An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.j... |
| CVE-2018-10813 | — | — | 1.1% | Jun 5, 2018 | In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visib... |
| CVE-2018-1000200 | — | — | 0.5% | Jun 5, 2018 | The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM)... |
| CVE-2018-1000181 | — | — | 1.5% | Jun 5, 2018 | Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a cra... |
| CVE-2018-1000180 | — | — | 3.6% | Jun 5, 2018 | Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key p... |
| CVE-2018-1252 | — | — | 2.0% | Jun 5, 2018 | RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensi... |
| CVE-2018-11722 | — | — | 1.5% | Jun 5, 2018 | WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded. |
| CVE-2018-11740 | — | — | 1.3% | Jun 5, 2018 | An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds re... |
| CVE-2018-11739 | — | — | 1.3% | Jun 5, 2018 | An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds rea... |
| CVE-2018-11738 | — | — | 1.3% | Jun 5, 2018 | An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read... |
| CVE-2018-11737 | — | — | 1.3% | Jun 5, 2018 | An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read... |
| CVE-2018-11678 | — | — | 1.7% | Jun 5, 2018 | plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_... |
| CVE-2018-11554 | — | — | 1.4% | Jun 5, 2018 | The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Dis... |
| CVE-2018-11736 | — | — | 8.6% | Jun 5, 2018 | An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute a... |
| CVE-2018-11735 | — | — | 0.8% | Jun 5, 2018 | index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter. |
| CVE-2018-11715 | — | — | 1.7% | Jun 4, 2018 | The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject. |
| CVE-2018-11714 | — | — | 36.5% | Jun 4, 2018 | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00... |
| CVE-2018-11713 | — | — | 1.6% | Jun 4, 2018 | WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKit... |
| CVE-2018-11712 | — | — | 1.2% | Jun 4, 2018 | WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKit... |
| CVE-2018-10615 | — | — | 2.6% | Jun 4, 2018 | Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise ve... |
| CVE-2018-10613 | — | — | 18.3% | Jun 4, 2018 | Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in ... |
| CVE-2018-10611 | — | — | 5.1% | Jun 4, 2018 | Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior ma... |
| CVE-2018-11711 | — | — | 5.3% | Jun 4, 2018 | A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now