2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5453 | — | — | 1.2% | Mar 5, 2018 | An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4... |
| CVE-2018-5449 | — | — | 0.5% | Mar 5, 2018 | A NULL Pointer Dereference issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. T... |
| CVE-2018-0491 | — | — | 15.6% | Mar 5, 2018 | A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of se... |
| CVE-2018-0490 | — | — | 2.7% | Mar 5, 2018 | An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-auth... |
| CVE-2018-7644 | — | — | 1.3% | Mar 5, 2018 | The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SA... |
| CVE-2018-1316 | — | — | 3.2% | Mar 5, 2018 | The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name ... |
| CVE-2018-1000115 | — | — | 88.6% | Mar 5, 2018 | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln... |
| CVE-2018-7668 | — | — | 1.5% | Mar 5, 2018 | TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachment... |
| CVE-2018-7667 | — | — | 4.6% | Mar 5, 2018 | Adminer through 4.3.1 has SSRF via the server parameter. |
| CVE-2018-7666 | — | — | 1.4% | Mar 5, 2018 | An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote... |
| CVE-2018-7665 | — | — | 16.4% | Mar 5, 2018 | An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter... |
| CVE-2018-7664 | — | — | 2.1% | Mar 5, 2018 | An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacter... |
| CVE-2018-7663 | — | — | 0.9% | Mar 5, 2018 | An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template li... |
| CVE-2018-7662 | — | — | 43.5% | Mar 4, 2018 | Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.fun... |
| CVE-2018-7661 | — | — | 0.9% | Mar 4, 2018 | Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests... |
| CVE-2018-7567 | — | — | 5.4% | Mar 4, 2018 | In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenti... |
| CVE-2018-7653 | — | — | 8.9% | Mar 4, 2018 | In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter. |
| CVE-2018-7654 | — | — | 2.5% | Mar 4, 2018 | On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access t... |
| CVE-2018-7651 | — | — | 1.8% | Mar 4, 2018 | index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in... |
| CVE-2018-7583 | — | — | 40.7% | Mar 4, 2018 | Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500. |
| CVE-2018-7449 | — | — | 7.9% | Mar 4, 2018 | SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in... |
| CVE-2018-7433 | — | — | 1.4% | Mar 2, 2018 | The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page. |
| CVE-2018-7643 | — | — | 2.5% | Mar 2, 2018 | The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (... |
| CVE-2018-7642 | — | — | 1.9% | Mar 2, 2018 | The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GN... |
| CVE-2018-1063 | — | — | 0.4% | Mar 2, 2018 | Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now