2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-1332Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that cou...
CVE-2018-7943There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass ...
CVE-2018-10966An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.j...
CVE-2018-10813In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visib...
CVE-2018-1000200The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM)...
CVE-2018-1000181Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a cra...
CVE-2018-1000180Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key p...
CVE-2018-1252RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensi...
CVE-2018-11722WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
CVE-2018-11740An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds re...
CVE-2018-11739An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds rea...
CVE-2018-11738An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read...
CVE-2018-11737An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read...
CVE-2018-11678plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_...
CVE-2018-11554The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Dis...
CVE-2018-11736An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute a...
CVE-2018-11735index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
CVE-2018-11715The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
CVE-2018-11714An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00...
CVE-2018-11713WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKit...
CVE-2018-11712WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKit...
CVE-2018-10615Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise ve...
CVE-2018-10613Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in ...
CVE-2018-10611Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior ma...
CVE-2018-11711A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now