2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12447 | — | — | 3.8% | Jun 15, 2018 | The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integ... |
| CVE-2018-1085 | CRITICAL | 9 | 2.2% | Jun 15, 2018 | openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificat... |
| CVE-2018-12440 | — | — | 0.1% | Jun 15, 2018 | BoringSSL through 2018-06-14 allows a memory-cache side-channel attack on DSA signatures, aka the Return Of the Hidden N... |
| CVE-2018-12439 | — | — | 0.3% | Jun 15, 2018 | MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden... |
| CVE-2018-12438 | MEDIUM | 4.9 | 0.5% | Jun 15, 2018 | The Elliptic Curve Cryptography library (aka sunec or libsunec) allows a memory-cache side-channel attack on ECDSA signa... |
| CVE-2018-12437 | MEDIUM | 4.9 | 0.5% | Jun 15, 2018 | LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden N... |
| CVE-2018-12436 | — | — | 0.4% | Jun 15, 2018 | wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka th... |
| CVE-2018-12435 | — | — | 0.5% | Jun 15, 2018 | Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of ... |
| CVE-2018-12434 | — | — | 0.3% | Jun 15, 2018 | LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka ... |
| CVE-2018-12433 | MEDIUM | 4.9 | 0.3% | Jun 15, 2018 | cryptlib through 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidd... |
| CVE-2018-12356 | — | — | 4.6% | Jun 15, 2018 | An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verifica... |
| CVE-2018-12432 | — | — | 0.7% | Jun 14, 2018 | JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI. |
| CVE-2018-12431 | — | — | 0.5% | Jun 14, 2018 | SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page). |
| CVE-2018-6516 | — | — | 0.8% | Jun 14, 2018 | On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-cli... |
| CVE-2018-12423 | — | — | 1.8% | Jun 14, 2018 | In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force. |
| CVE-2018-12420 | — | — | 1.0% | Jun 14, 2018 | IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request. |
| CVE-2018-8819 | — | — | 3.1% | Jun 14, 2018 | An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated a... |
| CVE-2018-11690 | — | — | 33.5% | Jun 14, 2018 | The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, cau... |
| CVE-2018-11689 | MEDIUM | 6.1 | 1.6% | Jun 14, 2018 | Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi... |
| CVE-2018-11574 | CRITICAL | 9.8 | 1.9% | Jun 14, 2018 | Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a c... |
| CVE-2018-12421 | — | — | 2.8% | Jun 14, 2018 | LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old pas... |
| CVE-2018-12114 | — | — | 3.0% | Jun 14, 2018 | Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. |
| CVE-2018-4848 | — | — | 1.0% | Jun 14, 2018 | A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3),... |
| CVE-2018-4842 | — | — | 0.8% | Jun 14, 2018 | A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.... |
| CVE-2018-4833 | — | — | 1.0% | Jun 14, 2018 | A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now