2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5500 | — | — | 1.4% | Mar 1, 2018 | On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection estab... |
| CVE-2018-7561 | — | — | 1.8% | Mar 1, 2018 | Stack-based Buffer Overflow in httpd on Tenda AC9 devices V15.03.05.14_EN allows remote attackers to cause a denial of s... |
| CVE-2018-6653 | — | — | 0.4% | Mar 1, 2018 | comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comfor... |
| CVE-2018-6947 | — | — | 3.2% | Feb 28, 2018 | An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM... |
| CVE-2018-7570 | — | — | 1.5% | Feb 28, 2018 | The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbf... |
| CVE-2018-7569 | — | — | 2.1% | Feb 28, 2018 | dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote at... |
| CVE-2018-7568 | — | — | 2.0% | Feb 28, 2018 | The parse_die function in dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binut... |
| CVE-2018-1304 | — | — | 17.7% | Feb 28, 2018 | The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomc... |
| CVE-2018-1286 | — | — | 1.1% | Feb 28, 2018 | In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authent... |
| CVE-2018-7264 | — | — | 13.0% | Feb 28, 2018 | The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out ... |
| CVE-2018-7469 | — | — | 0.5% | Feb 28, 2018 | PHP Scripts Mall Entrepreneur Job Portal Script 2.0.9 has XSS via the p_name (aka Edit Category Name) field to admin/cat... |
| CVE-2018-7556 | — | — | 2.0% | Feb 28, 2018 | LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerCon... |
| CVE-2018-7482 | — | — | 2.4% | Feb 28, 2018 | The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to downlo... |
| CVE-2018-7477 | — | — | 2.8% | Feb 28, 2018 | SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/... |
| CVE-2018-7554 | — | — | 2.3% | Feb 28, 2018 | There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted inpu... |
| CVE-2018-7553 | — | — | 2.5% | Feb 28, 2018 | There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will ... |
| CVE-2018-7552 | — | — | 2.3% | Feb 28, 2018 | There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4... |
| CVE-2018-7551 | — | — | 2.3% | Feb 28, 2018 | There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted ... |
| CVE-2018-7549 | — | — | 2.7% | Feb 27, 2018 | In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p. |
| CVE-2018-7548 | — | — | 2.6% | Feb 27, 2018 | In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result. |
| CVE-2018-7467 | — | — | 10.5% | Feb 27, 2018 | AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI. |
| CVE-2018-7542 | — | — | 0.4% | Feb 27, 2018 | An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL p... |
| CVE-2018-7541 | — | — | 0.4% | Feb 27, 2018 | An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or... |
| CVE-2018-7540 | — | — | 0.4% | Feb 27, 2018 | An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU h... |
| CVE-2018-6535 | — | — | 1.4% | Feb 27, 2018 | An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclo... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now