2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7641 | — | — | 1.3% | Mar 2, 2018 | An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted... |
| CVE-2018-7640 | — | — | 1.3% | Mar 2, 2018 | An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted... |
| CVE-2018-7639 | — | — | 1.3% | Mar 2, 2018 | An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted... |
| CVE-2018-7638 | — | — | 1.3% | Mar 2, 2018 | An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted... |
| CVE-2018-7637 | — | — | 1.3% | Mar 2, 2018 | An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted... |
| CVE-2018-1066 | — | — | 3.6% | Mar 2, 2018 | The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_r... |
| CVE-2018-1065 | — | — | 0.4% | Mar 2, 2018 | The netfilter subsystem in the Linux kernel through 4.15.7 mishandles the case of a rule blob that contains a jump but l... |
| CVE-2018-1169 | — | — | 2.6% | Mar 2, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player ... |
| CVE-2018-7634 | — | — | 0.8% | Mar 1, 2018 | An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it... |
| CVE-2018-7590 | — | — | 0.6% | Mar 1, 2018 | CSRF exists in Hoosk 1.7.0 via /admin/users/new/add, resulting in account creation. |
| CVE-2018-7589 | — | — | 1.4% | Mar 1, 2018 | An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image. |
| CVE-2018-7588 | — | — | 1.4% | Mar 1, 2018 | An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted... |
| CVE-2018-7587 | — | — | 1.1% | Mar 1, 2018 | An issue was discovered in CImg v.220. DoS occurs when loading a crafted bmp image that triggers an allocation failure i... |
| CVE-2018-7586 | — | — | 2.1% | Mar 1, 2018 | In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured. |
| CVE-2018-7049 | — | — | 0.9% | Mar 1, 2018 | An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com... |
| CVE-2018-7048 | — | — | 1.5% | Mar 1, 2018 | An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a ... |
| CVE-2018-7047 | — | — | 2.4% | Mar 1, 2018 | An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and wri... |
| CVE-2018-7584 | — | — | 87.9% | Mar 1, 2018 | In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer... |
| CVE-2018-7579 | — | — | 1.0% | Mar 1, 2018 | \application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to ad... |
| CVE-2018-7573 | — | — | 70.2% | Mar 1, 2018 | An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t... |
| CVE-2018-5314 | — | — | 2.9% | Mar 1, 2018 | Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build... |
| CVE-2018-2368 | — | — | 2.6% | Mar 1, 2018 | SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication chec... |
| CVE-2018-2367 | — | — | 2.0% | Mar 1, 2018 | ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an ... |
| CVE-2018-2365 | — | — | 1.0% | Mar 1, 2018 | SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resul... |
| CVE-2018-5501 | — | — | 1.4% | Mar 1, 2018 | In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now