2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12658 | MEDIUM | 6.1 | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_... |
| CVE-2018-12657 | — | — | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/maste... |
| CVE-2018-12656 | — | — | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/member... |
| CVE-2018-12655 | — | — | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circu... |
| CVE-2018-12654 | — | — | 0.9% | Jun 22, 2018 | Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibl... |
| CVE-2018-1655 | MEDIUM | 4 | 0.4% | Jun 22, 2018 | IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. ... |
| CVE-2018-12649 | — | — | 1.5% | Jun 22, 2018 | An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force pr... |
| CVE-2018-12648 | — | — | 2.3% | Jun 22, 2018 | The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer derefere... |
| CVE-2018-12430 | — | — | — | Jun 22, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-12429. Reason: This candidate is a reservation ... |
| CVE-2018-12642 | — | — | 1.4% | Jun 22, 2018 | Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user. |
| CVE-2018-12641 | — | — | 2.1% | Jun 22, 2018 | An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion... |
| CVE-2018-12635 | — | — | 0.9% | Jun 22, 2018 | CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.... |
| CVE-2018-12634 | CRITICAL | 9.8 | 57.7% | Jun 22, 2018 | CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/lo... |
| CVE-2018-12633 | — | — | 0.3% | Jun 22, 2018 | An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_... |
| CVE-2018-12632 | — | — | 1.4% | Jun 21, 2018 | Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN param... |
| CVE-2018-12631 | — | — | 3.3% | Jun 21, 2018 | Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/tex... |
| CVE-2018-12630 | — | — | 1.6% | Jun 21, 2018 | NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI. |
| CVE-2018-3665 | MEDIUM | 5.6 | 0.6% | Jun 21, 2018 | System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentia... |
| CVE-2018-12613 | HIGH | 8.8 | 98.4% | Jun 21, 2018 | An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute... |
| CVE-2018-12581 | — | — | 1.8% | Jun 21, 2018 | An issue was discovered in js/designer/move.js in phpMyAdmin before 4.8.2. A Cross-Site Scripting vulnerability has been... |
| CVE-2018-7683 | — | — | 1.1% | Jun 21, 2018 | Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log f... |
| CVE-2018-7681 | — | — | 0.5% | Jun 21, 2018 | Micro Focus Solutions Business Manager versions prior to 11.4 allows JavaScript to be embedded in URLs placed in "Favori... |
| CVE-2018-7680 | — | — | 0.6% | Jun 21, 2018 | Micro Focus Solutions Business Manager versions prior to 11.4 can reflect back HTTP header values. |
| CVE-2018-7679 | — | — | 2.3% | Jun 21, 2018 | Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the ... |
| CVE-2018-12617 | HIGH | 7.5 | 25.3% | Jun 21, 2018 | qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now