2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10908MEDIUM6.5It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By upload...
CVE-2018-6922One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12...
CVE-2018-3778MEDIUM5.3Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.
CVE-2018-14526An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of ...
CVE-2018-11561HIGH7.5An integer overflow in the unprotected distributeToken function of a smart contract implementation for EETHER (EETHER), ...
CVE-2018-11769CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation ...
CVE-2018-12408HIGH7.5The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix Busines...
CVE-2018-15209ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (he...
CVE-2018-15203MEDIUM6.5An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to ad...
CVE-2018-15202An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/temp...
CVE-2018-15199AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
CVE-2018-15198An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a use...
CVE-2018-15197An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that...
CVE-2018-15193A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via ...
CVE-2018-15192An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access ...
CVE-2018-15178Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and cond...
CVE-2018-15177In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
CVE-2018-15176XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x00000...
CVE-2018-15175XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVar...
CVE-2018-15174XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and a...
CVE-2018-15173Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption ...
CVE-2018-15169A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 all...
CVE-2018-15168A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids ...
CVE-2018-15137CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)...
CVE-2018-5383MEDIUM6.8Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions bef...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now