2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1309 | — | — | 4.5% | May 23, 2018 | Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or... |
| CVE-2018-8176 | — | — | 22.1% | May 23, 2018 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly valida... |
| CVE-2018-11396 | — | — | 1.5% | May 23, 2018 | ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial ... |
| CVE-2018-7295 | — | — | 0.4% | May 23, 2018 | ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Messa... |
| CVE-2018-11334 | — | — | 0.3% | May 23, 2018 | Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of... |
| CVE-2018-11362 | — | — | 3.1% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/diss... |
| CVE-2018-11361 | — | — | 2.9% | May 22, 2018 | In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by a... |
| CVE-2018-11360 | — | — | 3.5% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epa... |
| CVE-2018-11359 | — | — | 2.9% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was ad... |
| CVE-2018-11358 | — | — | 2.8% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dis... |
| CVE-2018-11357 | — | — | 2.9% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive ... |
| CVE-2018-11356 | — | — | 2.9% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/disse... |
| CVE-2018-11355 | — | — | 3.2% | May 22, 2018 | In Wireshark 2.6.0, the RTCP dissector could crash. This was addressed in epan/dissectors/packet-rtcp.c by avoiding a bu... |
| CVE-2018-11354 | — | — | 2.8% | May 22, 2018 | In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by m... |
| CVE-2018-10095 | — | — | 87.0% | May 22, 2018 | Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script... |
| CVE-2018-10094 | — | — | 71.2% | May 22, 2018 | SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto... |
| CVE-2018-10092 | — | — | 2.0% | May 22, 2018 | The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging suppor... |
| CVE-2018-11384 | — | — | 1.1% | May 22, 2018 | The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds rea... |
| CVE-2018-11383 | — | — | 1.1% | May 22, 2018 | The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and app... |
| CVE-2018-11382 | — | — | 1.1% | May 22, 2018 | The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bound... |
| CVE-2018-11381 | — | — | 1.1% | May 22, 2018 | The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-o... |
| CVE-2018-11380 | — | — | 1.1% | May 22, 2018 | The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of... |
| CVE-2018-11379 | — | — | 1.2% | May 22, 2018 | The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-b... |
| CVE-2018-11378 | — | — | 1.1% | May 22, 2018 | The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM fil... |
| CVE-2018-11377 | — | — | 1.4% | May 22, 2018 | The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-b... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now