2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-1383A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privi...
CVE-2018-6952A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
CVE-2018-6951An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer derefe...
CVE-2018-6948In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer...
CVE-2018-6928PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.
CVE-2018-0488ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows ...
CVE-2018-0487ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a...
CVE-2018-6911The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS...
CVE-2018-6293Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
CVE-2018-6292Remote Code Execution in Saperion Web Client version 7.5.2 83166.
CVE-2018-1297When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could all...
CVE-2018-6942An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ...
CVE-2018-6930A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0...
CVE-2018-1214Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default...
CVE-2018-6927The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial ...
CVE-2018-6926In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on ce...
CVE-2018-6893controllers/member/Api.php in dayrui FineCms 5.2.0 has SQL Injection: a request with s=member,c=api,m=checktitle, and th...
CVE-2018-6506Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use o...
CVE-2018-6889An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a m...
CVE-2018-6888An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cro...
CVE-2018-6864Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile upd...
CVE-2018-6863SQL Injection exists in PHP Scripts Mall Select Your College Script 2.0.2 via a Login Parameter.
CVE-2018-6862Cross Site Scripting (XSS) exists in PHP Scripts Mall Bitcoin MLM Software 1.0.2 via a profile field.
CVE-2018-6912The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial o...
CVE-2018-6892An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now