2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-5500On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection estab...
CVE-2018-7561Stack-based Buffer Overflow in httpd on Tenda AC9 devices V15.03.05.14_EN allows remote attackers to cause a denial of s...
CVE-2018-6653comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comfor...
CVE-2018-6947An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM...
CVE-2018-7570The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbf...
CVE-2018-7569dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote at...
CVE-2018-7568The parse_die function in dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binut...
CVE-2018-1304The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomc...
CVE-2018-1286In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authent...
CVE-2018-7264The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out ...
CVE-2018-7469PHP Scripts Mall Entrepreneur Job Portal Script 2.0.9 has XSS via the p_name (aka Edit Category Name) field to admin/cat...
CVE-2018-7556LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerCon...
CVE-2018-7482The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to downlo...
CVE-2018-7477SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/...
CVE-2018-7554There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted inpu...
CVE-2018-7553There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will ...
CVE-2018-7552There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4...
CVE-2018-7551There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted ...
CVE-2018-7549In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.
CVE-2018-7548In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
CVE-2018-7467AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.
CVE-2018-7542An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL p...
CVE-2018-7541An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or...
CVE-2018-7540An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU h...
CVE-2018-6535An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclo...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now