2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12097 | — | — | 0.6% | Jun 19, 2018 | The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows ... |
| CVE-2018-12096 | — | — | 0.6% | Jun 19, 2018 | The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote ... |
| CVE-2018-11731 | — | — | 1.2% | Jun 19, 2018 | The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote ... |
| CVE-2018-11730 | — | — | 0.8% | Jun 19, 2018 | The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 20... |
| CVE-2018-11729 | — | — | 1.2% | Jun 19, 2018 | The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote atta... |
| CVE-2018-11728 | MEDIUM | 5.5 | 1.2% | Jun 19, 2018 | The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-2... |
| CVE-2018-11727 | MEDIUM | 5.5 | 1.2% | Jun 19, 2018 | The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote at... |
| CVE-2018-11726 | — | — | 2.5% | Jun 19, 2018 | The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (he... |
| CVE-2018-11725 | — | — | 2.5% | Jun 19, 2018 | The mobi_parse_index_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure... |
| CVE-2018-11724 | — | — | 1.6% | Jun 19, 2018 | The mobi_pk1_decrypt function in encryption.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-... |
| CVE-2018-11723 | — | — | 1.2% | Jun 19, 2018 | The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remo... |
| CVE-2018-11116 | HIGH | 8.8 | 2.4% | Jun 19, 2018 | OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authentic... |
| CVE-2018-10945 | — | — | 1.4% | Jun 19, 2018 | The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-bas... |
| CVE-2018-10811 | HIGH | 7.5 | 7.4% | Jun 19, 2018 | strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. |
| CVE-2018-8727 | HIGH | 7.5 | 7.8% | Jun 19, 2018 | Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system ... |
| CVE-2018-6210 | CRITICAL | 9.8 | 3.1% | Jun 19, 2018 | D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which mak... |
| CVE-2018-11537 | — | — | 1.1% | Jun 19, 2018 | Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers ... |
| CVE-2018-11526 | — | — | 5.2% | Jun 19, 2018 | The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection. |
| CVE-2018-11525 | — | — | 5.2% | Jun 19, 2018 | The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection. |
| CVE-2018-12583 | — | — | 0.5% | Jun 19, 2018 | An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php. |
| CVE-2018-12582 | — | — | 0.6% | Jun 19, 2018 | An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&... |
| CVE-2018-12580 | — | — | 0.6% | Jun 19, 2018 | library/DBTech/Security/Action/Sessions.php in DragonByte vBSecurity 3.x through 3.3.0 for vBulletin 3 and vBulletin 4 a... |
| CVE-2018-12578 | — | — | 2.1% | Jun 19, 2018 | There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of ser... |
| CVE-2018-1073 | MEDIUM | 5.3 | 1.9% | Jun 19, 2018 | The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and inv... |
| CVE-2018-1061 | MEDIUM | 6.5 | 5.0% | Jun 19, 2018 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the dif... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now