2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-7269The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduc...
CVE-2018-8883Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled a...
CVE-2018-8882Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a la...
CVE-2018-8881Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related...
CVE-2018-8876In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po...
CVE-2018-8875In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po...
CVE-2018-8874In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po...
CVE-2018-8873In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)...
CVE-2018-8832enhavo 0.4.0 has XSS via a user-group that contains executable JavaScript code in the user-group name. The XSS attack la...
CVE-2018-8828A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially...
CVE-2018-3626Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible...
CVE-2018-5768A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted ...
CVE-2018-1141When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce se...
CVE-2018-5438Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker c...
CVE-2018-1322An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupporte...
CVE-2018-1321An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and un...
CVE-2018-1294If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounc...
CVE-2018-7511In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer...
CVE-2018-5770An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, ...
CVE-2018-5717Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to u...
CVE-2018-1000135GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver ...
CVE-2018-8821windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafte...
CVE-2018-8815Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in...
CVE-2018-8811Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow...
CVE-2018-8810In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote atta...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now