2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-14418In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
CVE-2018-14415An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admi...
CVE-2018-14441An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.act...
CVE-2018-14440An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeMa...
CVE-2018-14439espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four d...
CVE-2018-14438In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl ...
CVE-2018-14437ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.
CVE-2018-14436ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.
CVE-2018-14435ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.
CVE-2018-14434ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.
CVE-2018-10870CRITICAL9.8redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use t...
CVE-2018-10869HIGH7.5redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker...
CVE-2018-14336TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w...
CVE-2018-12959The approveAndCall function of a smart contract implementation for Aditus (ADI), an Ethereum ERC20 token, allows attacke...
CVE-2018-9062MEDIUM6.8In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrar...
CVE-2018-3871HIGH7.8An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially cra...
CVE-2018-3870HIGH7.8An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially cra...
CVE-2018-3860HIGH7.8An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially cr...
CVE-2018-3859HIGH7.8An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially cr...
CVE-2018-3858HIGH7.8An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted ...
CVE-2018-3857HIGH7.8An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted ...
CVE-2018-14423Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in O...
CVE-2018-10620CRITICAL9.8AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could ...
CVE-2018-7602CRITICAL9.8A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows a...
CVE-2018-14332An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access viola...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now