2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11740An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds re...
CVE-2018-11739An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds rea...
CVE-2018-11738An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read...
CVE-2018-11737An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read...
CVE-2018-11678plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_...
CVE-2018-11554The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Dis...
CVE-2018-11736An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute a...
CVE-2018-11735index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
CVE-2018-3853HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software Foxit PDF Reader version 9...
CVE-2018-1600HIGH8.6IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel t...
CVE-2018-11715The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
CVE-2018-11714An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00...
CVE-2018-11713WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKit...
CVE-2018-11712WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKit...
CVE-2018-10615Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise ve...
CVE-2018-10613Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in ...
CVE-2018-10611Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior ma...
CVE-2018-11711A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN ...
CVE-2018-11710soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) o...
CVE-2018-11709wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unaut...
CVE-2018-9994Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-11698An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sas...
CVE-2018-11697An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sas...
CVE-2018-11696An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::op...
CVE-2018-11695An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator w...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now