2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12714CRITICAL9.8An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c cou...
CVE-2018-12706DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
CVE-2018-12705DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
CVE-2018-12713CRITICAL9.1GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that alre...
CVE-2018-12700Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-12699finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) o...
CVE-2018-12698demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger exce...
CVE-2018-12697A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cpl...
CVE-2018-12640CRITICAL9.8The webService binary on Insteon HD IP Camera White 2864-222 devices has a Buffer Overflow via a crafted pid, pwd, or us...
CVE-2018-11560CRITICAL9.8The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Contro...
CVE-2018-12696mao10cms 6 allows XSS via the article page.
CVE-2018-12695mao10cms 6 allows XSS via the m=bbs&a=index page.
CVE-2018-12694TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (re...
CVE-2018-12693Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticat...
CVE-2018-12692TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary c...
CVE-2018-7682Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domain...
CVE-2018-12689CRITICAL9.8phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a cra...
CVE-2018-12688tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.
CVE-2018-12687tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.
CVE-2018-12684Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Deni...
CVE-2018-12538In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persisten...
CVE-2018-12678Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query paramet...
CVE-2018-1000201ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used a...
CVE-2018-12636The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi...
CVE-2018-12659SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now