2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7490 | — | — | 70.8% | Feb 26, 2018 | uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversa... |
| CVE-2018-0908 | — | — | 2.6% | Feb 26, 2018 | Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a ... |
| CVE-2018-7492 | — | — | 0.7% | Feb 26, 2018 | A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 a... |
| CVE-2018-7250 | — | — | 3.0% | Feb 26, 2018 | An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 befor... |
| CVE-2018-7249 | — | — | 1.5% | Feb 26, 2018 | An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 befor... |
| CVE-2018-7491 | — | — | 1.1% | Feb 26, 2018 | In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing im... |
| CVE-2018-7448 | — | — | 13.3% | Feb 26, 2018 | Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote... |
| CVE-2018-7489 | — | — | 20.5% | Feb 26, 2018 | FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote co... |
| CVE-2018-7487 | — | — | 1.3% | Feb 26, 2018 | There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead t... |
| CVE-2018-5762 | — | — | 1.0% | Feb 26, 2018 | The TLS implementation in the TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 58.1 before 58.160... |
| CVE-2018-7486 | — | — | 2.6% | Feb 26, 2018 | Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper res... |
| CVE-2018-7485 | — | — | 3.2% | Feb 26, 2018 | The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, w... |
| CVE-2018-1377 | — | — | 0.3% | Feb 26, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be rea... |
| CVE-2018-7463 | — | — | 1.3% | Feb 26, 2018 | SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to ... |
| CVE-2018-7484 | — | — | 2.4% | Feb 26, 2018 | An issue was discovered in PureVPN through 5.19.4.0 on Windows. The client installation grants the Everyone group Full C... |
| CVE-2018-7476 | — | — | 0.9% | Feb 25, 2018 | controllers/admin/Linkage.php in dayrui FineCms 5.3.0 has Cross Site Scripting (XSS) via the id or lid parameter in a c=... |
| CVE-2018-7472 | — | — | 0.4% | Feb 25, 2018 | INVT Studio 1.2 allows remote attackers to cause a denial of service during import operations. |
| CVE-2018-7471 | — | — | 0.3% | Feb 25, 2018 | KingView 7.5SP1 has an integer overflow during stgopenstorage API read operations. |
| CVE-2018-7470 | — | — | 1.9% | Feb 25, 2018 | An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless function in coders/webp.c allows attackers ... |
| CVE-2018-7466 | — | — | 6.4% | Feb 25, 2018 | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging c... |
| CVE-2018-6883 | — | — | 1.3% | Feb 24, 2018 | Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an ... |
| CVE-2018-7456 | — | — | 3.1% | Feb 24, 2018 | A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.... |
| CVE-2018-7455 | — | — | 0.8% | Feb 24, 2018 | An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of servi... |
| CVE-2018-7454 | — | — | 0.8% | Feb 24, 2018 | A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of servic... |
| CVE-2018-7453 | — | — | 0.9% | Feb 24, 2018 | Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now