2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12714 | CRITICAL | 9.8 | 5.3% | Jun 24, 2018 | An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c cou... |
| CVE-2018-12706 | — | — | 10.0% | Jun 24, 2018 | DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header. |
| CVE-2018-12705 | — | — | 2.3% | Jun 24, 2018 | DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side). |
| CVE-2018-12713 | CRITICAL | 9.1 | 1.9% | Jun 24, 2018 | GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that alre... |
| CVE-2018-12700 | — | — | — | Jun 23, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-12699 | — | — | 4.5% | Jun 23, 2018 | finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) o... |
| CVE-2018-12698 | — | — | 6.7% | Jun 23, 2018 | demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger exce... |
| CVE-2018-12697 | — | — | 5.2% | Jun 23, 2018 | A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cpl... |
| CVE-2018-12640 | CRITICAL | 9.8 | 1.6% | Jun 23, 2018 | The webService binary on Insteon HD IP Camera White 2864-222 devices has a Buffer Overflow via a crafted pid, pwd, or us... |
| CVE-2018-11560 | CRITICAL | 9.8 | 1.6% | Jun 23, 2018 | The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Contro... |
| CVE-2018-12696 | — | — | 0.7% | Jun 23, 2018 | mao10cms 6 allows XSS via the article page. |
| CVE-2018-12695 | — | — | 0.7% | Jun 23, 2018 | mao10cms 6 allows XSS via the m=bbs&a=index page. |
| CVE-2018-12694 | — | — | 1.5% | Jun 23, 2018 | TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (re... |
| CVE-2018-12693 | — | — | 15.8% | Jun 23, 2018 | Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticat... |
| CVE-2018-12692 | — | — | 29.1% | Jun 23, 2018 | TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary c... |
| CVE-2018-7682 | — | — | 0.8% | Jun 22, 2018 | Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domain... |
| CVE-2018-12689 | CRITICAL | 9.8 | 1.8% | Jun 22, 2018 | phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a cra... |
| CVE-2018-12688 | — | — | 1.6% | Jun 22, 2018 | tinyexr 0.9.5 has a segmentation fault in the wav2Decode function. |
| CVE-2018-12687 | — | — | 1.4% | Jun 22, 2018 | tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h. |
| CVE-2018-12684 | — | — | 1.1% | Jun 22, 2018 | Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Deni... |
| CVE-2018-12538 | — | — | 2.7% | Jun 22, 2018 | In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persisten... |
| CVE-2018-12678 | — | — | 2.3% | Jun 22, 2018 | Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query paramet... |
| CVE-2018-1000201 | — | — | 1.4% | Jun 22, 2018 | ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used a... |
| CVE-2018-12636 | — | — | 30.1% | Jun 22, 2018 | The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi... |
| CVE-2018-12659 | — | — | 0.8% | Jun 22, 2018 | SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now