2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1612MEDIUM5.8IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and ...
CVE-2018-14347GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).
CVE-2018-14346GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
CVE-2018-14345An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not checked for us...
CVE-2018-13862Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker...
CVE-2018-13861Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allows unauthorized remote attacke...
CVE-2018-13860MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18 allo...
CVE-2018-13859MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all...
CVE-2018-13858MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional allows unauthorized remote attackers to ...
CVE-2018-6681MEDIUM5.4Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earli...
CVE-2018-14338samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple ...
CVE-2018-13864A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fix...
CVE-2018-14337HIGH7.5The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leadi...
CVE-2018-14334manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file exten...
CVE-2018-14333TeamViewer through 13.1.1548 stores a password in Unicode format within TeamViewer.exe process memory between "[00 88] a...
CVE-2018-14331An issue was discovered in XiaoCms X1 v20140305. There is a CSRF vulnerability to change the administrator account passw...
CVE-2018-14329MEDIUM4.7In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink att...
CVE-2018-0710Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe...
CVE-2018-0709Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth...
CVE-2018-0708Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo...
CVE-2018-0707Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could...
CVE-2018-0706Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate...
CVE-2018-13832Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu...
CVE-2018-12584CRITICAL9.8The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem...
CVE-2018-10857MEDIUM5.9git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now