2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8990 | — | — | 0.4% | Mar 25, 2018 | In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users ... |
| CVE-2018-8989 | — | — | 0.4% | Mar 25, 2018 | In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users ... |
| CVE-2018-8988 | — | — | 0.4% | Mar 25, 2018 | In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users ... |
| CVE-2018-8977 | — | — | 2.2% | Mar 25, 2018 | In Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denia... |
| CVE-2018-8975 | — | — | 1.7% | Mar 25, 2018 | The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denia... |
| CVE-2018-8973 | — | — | 0.7% | Mar 24, 2018 | OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add r... |
| CVE-2018-8972 | — | — | 0.6% | Mar 24, 2018 | Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configura... |
| CVE-2018-8971 | — | — | 1.3% | Mar 24, 2018 | The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-... |
| CVE-2018-8970 | — | — | 1.1% | Mar 24, 2018 | The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a... |
| CVE-2018-8964 | — | — | 1.7% | Mar 23, 2018 | In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. Remote attackers could leverage this... |
| CVE-2018-8963 | — | — | 1.5% | Mar 23, 2018 | In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. Remote attackers could leverage... |
| CVE-2018-8962 | — | — | 1.7% | Mar 23, 2018 | In libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free. Remote attacke... |
| CVE-2018-8961 | — | — | 1.5% | Mar 23, 2018 | In libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free. Remote attackers could leverage t... |
| CVE-2018-8960 | — | — | 4.5% | Mar 23, 2018 | The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, le... |
| CVE-2018-8957 | — | — | 0.8% | Mar 23, 2018 | CoverCMS v1.1.6 has XSS via the fourth input box to index.php, related to admina/mconfigs.inc.php. |
| CVE-2018-1000140 | — | — | 9.7% | Mar 23, 2018 | rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates... |
| CVE-2018-1000136 | — | — | 4.8% | Mar 23, 2018 | Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values ... |
| CVE-2018-8949 | — | — | 0.8% | Mar 23, 2018 | An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potenti... |
| CVE-2018-8948 | — | — | 0.8% | Mar 23, 2018 | In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module. |
| CVE-2018-7502 | — | — | 0.6% | Mar 23, 2018 | Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of use... |
| CVE-2018-1211 | — | — | 3.3% | Mar 23, 2018 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI par... |
| CVE-2018-1207 | — | — | 90.8% | Mar 23, 2018 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute... |
| CVE-2018-8945 | — | — | 2.1% | Mar 22, 2018 | The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in ... |
| CVE-2018-8944 | — | — | 1.2% | Mar 22, 2018 | PHPOK 4.8.338 has an arbitrary file upload vulnerability. |
| CVE-2018-8943 | — | — | 1.1% | Mar 22, 2018 | There is a SQL injection in the PHPSHE 1.6 userbank parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now