2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11576 | — | — | 1.4% | May 31, 2018 | ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor. |
| CVE-2018-11575 | — | — | 1.5% | May 31, 2018 | ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg. |
| CVE-2018-11572 | — | — | 0.7% | May 31, 2018 | ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI. |
| CVE-2018-11571 | — | — | 1.3% | May 31, 2018 | ClipperCMS 1.3.3 allows Session Fixation. |
| CVE-2018-11568 | — | — | 1.1% | May 30, 2018 | Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitizatio... |
| CVE-2018-11567 | — | — | 1.1% | May 30, 2018 | Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt ... |
| CVE-2018-7534 | — | — | 0.2% | May 30, 2018 | In Stealth Authorization Server before 3.3.017.0 in Unisys Stealth Solution, an encryption key may be left in memory. |
| CVE-2018-11565 | — | — | 0.9% | May 30, 2018 | Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames... |
| CVE-2018-11482 | — | — | 1.2% | May 30, 2018 | /usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a... |
| CVE-2018-11481 | — | — | 1.8% | May 30, 2018 | TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execu... |
| CVE-2018-11478 | — | — | 0.9% | May 30, 2018 | An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and ... |
| CVE-2018-11477 | — | — | 0.5% | May 30, 2018 | An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or And... |
| CVE-2018-11476 | — | — | 0.5% | May 30, 2018 | An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that can... |
| CVE-2018-10939 | — | — | 1.4% | May 30, 2018 | Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persisten... |
| CVE-2018-10196 | — | — | 1.7% | May 30, 2018 | NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Grap... |
| CVE-2018-11562 | — | — | 0.8% | May 30, 2018 | An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if ... |
| CVE-2018-11518 | — | — | 1.4% | May 30, 2018 | A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on vari... |
| CVE-2018-10995 | — | — | 1.7% | May 30, 2018 | SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka... |
| CVE-2018-11438 | — | — | 2.7% | May 30, 2018 | The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution... |
| CVE-2018-11437 | — | — | 1.4% | May 30, 2018 | The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclos... |
| CVE-2018-11436 | — | — | 1.4% | May 30, 2018 | The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-base... |
| CVE-2018-11435 | — | — | 1.4% | May 30, 2018 | The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause informati... |
| CVE-2018-11434 | — | — | 1.4% | May 30, 2018 | The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap... |
| CVE-2018-11433 | — | — | 1.4% | May 30, 2018 | The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclo... |
| CVE-2018-11432 | — | — | 1.4% | May 30, 2018 | The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (hea... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now