2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12447The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integ...
CVE-2018-1085CRITICAL9openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificat...
CVE-2018-12440BoringSSL through 2018-06-14 allows a memory-cache side-channel attack on DSA signatures, aka the Return Of the Hidden N...
CVE-2018-12439MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden...
CVE-2018-12438MEDIUM4.9The Elliptic Curve Cryptography library (aka sunec or libsunec) allows a memory-cache side-channel attack on ECDSA signa...
CVE-2018-12437MEDIUM4.9LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden N...
CVE-2018-12436wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka th...
CVE-2018-12435Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of ...
CVE-2018-12434LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka ...
CVE-2018-12433MEDIUM4.9cryptlib through 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidd...
CVE-2018-12356An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verifica...
CVE-2018-12432JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
CVE-2018-12431SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).
CVE-2018-6516On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-cli...
CVE-2018-12423In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
CVE-2018-12420IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
CVE-2018-8819An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated a...
CVE-2018-11690The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, cau...
CVE-2018-11689MEDIUM6.1Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi...
CVE-2018-11574CRITICAL9.8Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a c...
CVE-2018-12421LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old pas...
CVE-2018-12114Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
CVE-2018-4848A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3),...
CVE-2018-4842A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4....
CVE-2018-4833A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now