2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10908 | MEDIUM | 6.5 | 1.2% | Aug 9, 2018 | It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By upload... |
| CVE-2018-6922 | — | — | 3.2% | Aug 9, 2018 | One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12... |
| CVE-2018-3778 | MEDIUM | 5.3 | 1.4% | Aug 8, 2018 | Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized. |
| CVE-2018-14526 | — | — | 1.4% | Aug 8, 2018 | An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of ... |
| CVE-2018-11561 | HIGH | 7.5 | 0.9% | Aug 8, 2018 | An integer overflow in the unprotected distributeToken function of a smart contract implementation for EETHER (EETHER), ... |
| CVE-2018-11769 | — | — | 8.2% | Aug 8, 2018 | CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation ... |
| CVE-2018-12408 | HIGH | 7.5 | 2.4% | Aug 8, 2018 | The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix Busines... |
| CVE-2018-15209 | — | — | 4.0% | Aug 8, 2018 | ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (he... |
| CVE-2018-15203 | MEDIUM | 6.5 | 0.4% | Aug 8, 2018 | An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to ad... |
| CVE-2018-15202 | — | — | 0.4% | Aug 8, 2018 | An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/temp... |
| CVE-2018-15199 | — | — | 0.6% | Aug 8, 2018 | AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action. |
| CVE-2018-15198 | — | — | 0.7% | Aug 8, 2018 | An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a use... |
| CVE-2018-15197 | — | — | 0.7% | Aug 8, 2018 | An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that... |
| CVE-2018-15193 | — | — | 0.8% | Aug 8, 2018 | A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via ... |
| CVE-2018-15192 | — | — | 2.1% | Aug 8, 2018 | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access ... |
| CVE-2018-15178 | — | — | 1.3% | Aug 8, 2018 | Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and cond... |
| CVE-2018-15177 | — | — | 0.6% | Aug 8, 2018 | In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. |
| CVE-2018-15176 | — | — | 1.0% | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x00000... |
| CVE-2018-15175 | — | — | 1.0% | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVar... |
| CVE-2018-15174 | — | — | 1.0% | Aug 8, 2018 | XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and a... |
| CVE-2018-15173 | — | — | 6.1% | Aug 8, 2018 | Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption ... |
| CVE-2018-15169 | — | — | 1.7% | Aug 8, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 all... |
| CVE-2018-15168 | — | — | 3.9% | Aug 8, 2018 | A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids ... |
| CVE-2018-15137 | — | — | 18.2% | Aug 8, 2018 | CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)... |
| CVE-2018-5383 | MEDIUM | 6.8 | 0.8% | Aug 7, 2018 | Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions bef... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now