2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-5453An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4...
CVE-2018-5449A NULL Pointer Dereference issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. T...
CVE-2018-0491A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of se...
CVE-2018-0490An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-auth...
CVE-2018-7644The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SA...
CVE-2018-1316The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name ...
CVE-2018-1000115Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln...
CVE-2018-7668TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachment...
CVE-2018-7667Adminer through 4.3.1 has SSRF via the server parameter.
CVE-2018-7666An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote...
CVE-2018-7665An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter...
CVE-2018-7664An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacter...
CVE-2018-7663An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template li...
CVE-2018-7662Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.fun...
CVE-2018-7661Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests...
CVE-2018-7567In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenti...
CVE-2018-7653In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
CVE-2018-7654On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access t...
CVE-2018-7651index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in...
CVE-2018-7583Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500.
CVE-2018-7449SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in...
CVE-2018-7433The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
CVE-2018-7643The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (...
CVE-2018-7642The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GN...
CVE-2018-1063Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now