2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10777 | — | — | 1.0% | May 7, 2018 | Buffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain through 1.5.2-r2 allows remote attackers to ca... |
| CVE-2018-10776 | — | — | 1.0% | May 7, 2018 | The getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of serv... |
| CVE-2018-10775 | — | — | 1.7% | May 7, 2018 | NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote a... |
| CVE-2018-10774 | — | — | 1.4% | May 7, 2018 | Read access violation in the isiin_keyword function in isiin.c in libbibutils.a in bibutils through 6.2 allows remote at... |
| CVE-2018-10773 | — | — | 1.2% | May 7, 2018 | NULL pointer deference in the addsn function in serialno.c in libbibcore.a in bibutils through 6.2 allows remote attacke... |
| CVE-2018-10772 | — | — | 1.6% | May 7, 2018 | The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (a... |
| CVE-2018-10768 | — | — | 2.4% | May 6, 2018 | There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppl... |
| CVE-2018-10767 | — | — | 2.3% | May 6, 2018 | There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c ... |
| CVE-2018-0494 | — | — | 17.2% | May 6, 2018 | GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen... |
| CVE-2018-10686 | — | — | 1.3% | May 6, 2018 | An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/i... |
| CVE-2018-10723 | — | — | 1.3% | May 5, 2018 | Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql. |
| CVE-2018-10758 | — | — | 0.5% | May 5, 2018 | The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles. |
| CVE-2018-10757 | — | — | 5.8% | May 5, 2018 | CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a ... |
| CVE-2018-10754 | — | — | — | May 5, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-10752 | — | — | 1.9% | May 5, 2018 | The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action. |
| CVE-2018-9154 | — | — | 3.5% | May 4, 2018 | There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lea... |
| CVE-2018-10251 | — | — | 4.5% | May 4, 2018 | A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ... |
| CVE-2018-10229 | — | — | 0.6% | May 4, 2018 | A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the us... |
| CVE-2018-7509 | — | — | 2.6% | May 4, 2018 | WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of the intended buffer... |
| CVE-2018-7507 | — | — | 2.9% | May 4, 2018 | WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the... |
| CVE-2018-7494 | — | — | 2.9% | May 4, 2018 | WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than th... |
| CVE-2018-10750 | — | — | 3.3% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet... |
| CVE-2018-10749 | — | — | 2.7% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' p... |
| CVE-2018-10748 | — | — | 2.7% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' par... |
| CVE-2018-10747 | — | — | 2.7% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' p... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now