2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-5521On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect a...
CVE-2018-5513On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handsh...
CVE-2018-11651Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/...
CVE-2018-11650Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNot...
CVE-2018-11649Hue 3.12 has XSS via the /pig/save/ name and script parameters.
CVE-2018-11646webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon...
CVE-2018-11645psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow ...
CVE-2018-9186A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF valida...
CVE-2018-6552Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as...
CVE-2018-10379An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5...
CVE-2018-11633An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can b...
CVE-2018-11632An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPres...
CVE-2018-11631Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notificatio...
CVE-2018-11627Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
CVE-2018-11626SELA (aka SimplE Lossless Audio) v0.1.2-alpha has a stack-based buffer overflow in the core/apev2.c init_apev2_keys func...
CVE-2018-11142The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management App...
CVE-2018-11141The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE Syste...
CVE-2018-11140The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8...
CVE-2018-11139The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible ...
CVE-2018-11137The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8...
CVE-2018-11136The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management ...
CVE-2018-11134In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies o...
CVE-2018-11133The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.3...
CVE-2018-11132In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on...
CVE-2018-11625In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now