2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1092 | — | — | 2.0% | Apr 2, 2018 | The ext4_iget function in fs/ext4/inode.c in the Linux kernel through 4.15.15 mishandles the case of a root directory wi... |
| CVE-2018-9172 | — | — | 3.2% | Apr 1, 2018 | The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. |
| CVE-2018-9165 | — | — | 1.1% | Apr 1, 2018 | The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to... |
| CVE-2018-9158 | — | — | 1.3% | Apr 1, 2018 | An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mech... |
| CVE-2018-9157 | — | — | 3.2% | Apr 1, 2018 | An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verif... |
| CVE-2018-9156 | — | — | 3.9% | Apr 1, 2018 | An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify ... |
| CVE-2018-9149 | — | — | 0.5% | Apr 1, 2018 | The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an at... |
| CVE-2018-6849 | — | — | 30.1% | Apr 1, 2018 | In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati... |
| CVE-2018-9128 | — | — | 4.9% | Apr 1, 2018 | DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068. |
| CVE-2018-9162 | — | — | 2.4% | Mar 31, 2018 | Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.... |
| CVE-2018-9161 | — | — | 58.5% | Mar 31, 2018 | Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the... |
| CVE-2018-8908 | — | — | 2.4% | Mar 31, 2018 | An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CS... |
| CVE-2018-8893 | — | — | 0.5% | Mar 31, 2018 | Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code. |
| CVE-2018-9160 | — | — | 76.5% | Mar 31, 2018 | SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. |
| CVE-2018-9159 | — | — | 4.6% | Mar 31, 2018 | In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or rel... |
| CVE-2018-7566 | — | — | 0.5% | Mar 30, 2018 | The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq... |
| CVE-2018-7203 | — | — | 2.4% | Mar 30, 2018 | Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary... |
| CVE-2018-7171 | — | — | 28.2% | Mar 30, 2018 | Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a... |
| CVE-2018-5708 | — | — | 6.3% | Mar 30, 2018 | An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat... |
| CVE-2018-1234 | — | — | 0.5% | Mar 30, 2018 | RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (A... |
| CVE-2018-1233 | — | — | 1.1% | Mar 30, 2018 | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-si... |
| CVE-2018-1232 | — | — | 2.8% | Mar 30, 2018 | RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-ba... |
| CVE-2018-3819 | — | — | 0.9% | Mar 30, 2018 | The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 h... |
| CVE-2018-3818 | — | — | 0.9% | Mar 30, 2018 | Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter... |
| CVE-2018-3817 | — | — | 1.0% | Mar 30, 2018 | When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now