2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11694 | — | — | 1.7% | Jun 4, 2018 | An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::... |
| CVE-2018-11693 | — | — | 1.4% | Jun 4, 2018 | An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sas... |
| CVE-2018-11692 | — | — | 4.6% | Jun 4, 2018 | An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administr... |
| CVE-2018-11685 | — | — | 2.2% | Jun 4, 2018 | Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c. |
| CVE-2018-11684 | — | — | 2.2% | Jun 4, 2018 | Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c. |
| CVE-2018-11683 | — | — | 2.2% | Jun 4, 2018 | Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vu... |
| CVE-2018-10762 | — | — | — | Jun 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-10761 | — | — | — | Jun 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-11682 | CRITICAL | 9.8 | 4.3% | Jun 2, 2018 | Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a ... |
| CVE-2018-11681 | CRITICAL | 9.8 | 4.3% | Jun 2, 2018 | Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of... |
| CVE-2018-11629 | — | — | 4.3% | Jun 2, 2018 | Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user ... |
| CVE-2018-11680 | — | — | 0.4% | Jun 2, 2018 | An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an I... |
| CVE-2018-11679 | — | — | 0.5% | Jun 2, 2018 | An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?ca... |
| CVE-2018-11564 | — | — | 3.2% | Jun 2, 2018 | Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.... |
| CVE-2018-11522 | — | — | 4.3% | Jun 2, 2018 | Yosoro 1.0.4 has stored XSS. |
| CVE-2018-11194 | — | — | 2.7% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 6 of 6). |
| CVE-2018-11193 | — | — | 2.7% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 5 of 6). |
| CVE-2018-11192 | — | — | 2.7% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 4 of 6). |
| CVE-2018-11191 | — | — | 2.7% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 3 of 6). |
| CVE-2018-11190 | — | — | 2.7% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 2 of 6). |
| CVE-2018-11189 | — | — | 3.4% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 1 of 6). |
| CVE-2018-11188 | — | — | 4.6% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 46 of 46). |
| CVE-2018-11187 | — | — | 4.6% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 45 of 46). |
| CVE-2018-11186 | — | — | 4.6% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 44 of 46). |
| CVE-2018-11185 | — | — | 4.6% | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 43 of 46). |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now