2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11418 | — | — | 1.6% | May 24, 2018 | An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_utf8 f... |
| CVE-2018-11416 | — | — | 1.8% | May 24, 2018 | jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attacker... |
| CVE-2018-11415 | — | — | 8.3% | May 24, 2018 | SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: th... |
| CVE-2018-11414 | — | — | 1.1% | May 24, 2018 | An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\contr... |
| CVE-2018-11413 | — | — | 1.6% | May 24, 2018 | An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.htm... |
| CVE-2018-11412 | — | — | 16.4% | May 24, 2018 | In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste... |
| CVE-2018-8013 | — | — | 19.5% | May 24, 2018 | In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the in... |
| CVE-2018-11332 | — | — | 1.9% | May 24, 2018 | Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in... |
| CVE-2018-10595 | — | — | 0.4% | May 24, 2018 | A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a... |
| CVE-2018-10593 | — | — | 0.4% | May 24, 2018 | A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorize... |
| CVE-2018-7942 | — | — | 1.6% | May 24, 2018 | The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have an authentication bypass vulnerabilit... |
| CVE-2018-7904 | — | — | 1.1% | May 24, 2018 | Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote a... |
| CVE-2018-7903 | — | — | 1.1% | May 24, 2018 | Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote a... |
| CVE-2018-7902 | — | — | 1.1% | May 24, 2018 | Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote a... |
| CVE-2018-5487 | — | — | 2.9% | May 24, 2018 | NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Metho... |
| CVE-2018-5485 | — | — | 0.4% | May 24, 2018 | NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lea... |
| CVE-2018-9920 | — | — | 0.8% | May 24, 2018 | Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an http... |
| CVE-2018-1000300 | — | — | 4.9% | May 24, 2018 | curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in de... |
| CVE-2018-1000199 | — | — | 1.2% | May 24, 2018 | The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result ... |
| CVE-2018-1000155 | — | — | 1.2% | May 24, 2018 | OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake... |
| CVE-2018-1000040 | — | — | 1.5% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker ... |
| CVE-2018-1000038 | — | — | 2.0% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could al... |
| CVE-2018-11411 | — | — | 1.0% | May 24, 2018 | The transferFrom function of a smart contract implementation for DimonCoin (FUD), an Ethereum ERC20 token, allows attack... |
| CVE-2018-11410 | — | — | 5.1% | May 24, 2018 | An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allow... |
| CVE-2018-11405 | — | — | 0.6% | May 24, 2018 | Kliqqi 2.0.2 has CSRF in admin/admin_users.php. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now