2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5521 | — | — | 0.9% | Jun 1, 2018 | On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect a... |
| CVE-2018-5513 | — | — | 1.8% | Jun 1, 2018 | On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handsh... |
| CVE-2018-11651 | — | — | 0.8% | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/... |
| CVE-2018-11650 | — | — | 0.8% | Jun 1, 2018 | Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNot... |
| CVE-2018-11649 | — | — | 0.7% | Jun 1, 2018 | Hue 3.12 has XSS via the /pig/save/ name and script parameters. |
| CVE-2018-11646 | — | — | 69.0% | Jun 1, 2018 | webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon... |
| CVE-2018-11645 | — | — | 2.6% | Jun 1, 2018 | psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow ... |
| CVE-2018-9186 | — | — | 0.8% | May 31, 2018 | A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF valida... |
| CVE-2018-6552 | — | — | 0.4% | May 31, 2018 | Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as... |
| CVE-2018-10379 | — | — | 0.9% | May 31, 2018 | An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5... |
| CVE-2018-11633 | — | — | 0.5% | May 31, 2018 | An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can b... |
| CVE-2018-11632 | — | — | 0.5% | May 31, 2018 | An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPres... |
| CVE-2018-11631 | — | — | 1.2% | May 31, 2018 | Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notificatio... |
| CVE-2018-11627 | — | — | 2.2% | May 31, 2018 | Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. |
| CVE-2018-11626 | — | — | 1.4% | May 31, 2018 | SELA (aka SimplE Lossless Audio) v0.1.2-alpha has a stack-based buffer overflow in the core/apev2.c init_apev2_keys func... |
| CVE-2018-11142 | — | — | 0.4% | May 31, 2018 | The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management App... |
| CVE-2018-11141 | — | — | 2.0% | May 31, 2018 | The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE Syste... |
| CVE-2018-11140 | — | — | 1.4% | May 31, 2018 | The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8... |
| CVE-2018-11139 | — | — | 42.9% | May 31, 2018 | The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible ... |
| CVE-2018-11137 | — | — | 6.5% | May 31, 2018 | The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8... |
| CVE-2018-11136 | — | — | 1.4% | May 31, 2018 | The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management ... |
| CVE-2018-11134 | — | — | 3.0% | May 31, 2018 | In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies o... |
| CVE-2018-11133 | — | — | 7.3% | May 31, 2018 | The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.3... |
| CVE-2018-11132 | — | — | 18.3% | May 31, 2018 | In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on... |
| CVE-2018-11625 | — | — | 2.3% | May 31, 2018 | In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now