2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11136The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management ...
CVE-2018-11135HIGH8.8The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users...
CVE-2018-11134In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies o...
CVE-2018-11133The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.3...
CVE-2018-11132In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on...
CVE-2018-11625In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over...
CVE-2018-11624In ImageMagick 7.0.7-36 Q16, the ReadMATImage function in coders/mat.c allows attackers to cause a use after free via a ...
CVE-2018-11598Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Discl...
CVE-2018-11597Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file vi...
CVE-2018-11596Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file vi...
CVE-2018-11595Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Escalation of Pri...
CVE-2018-11594Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file vi...
CVE-2018-11593Espruino before 1.99 allows attackers to cause a denial of service (application crash) and potential Information Disclos...
CVE-2018-11592Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file vi...
CVE-2018-11591Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file vi...
CVE-2018-11590Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file vi...
CVE-2018-11220Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.
CVE-2018-5388In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may l...
CVE-2018-9322The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 S...
CVE-2018-9320The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 S...
CVE-2018-9318The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 thro...
CVE-2018-9314The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 S...
CVE-2018-9313The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 S...
CVE-2018-9312The Head Unit HU_NBT (aka Infotainment) component on BMW i Series, BMW X Series, BMW 3 Series, BMW 5 Series, and BMW 7 S...
CVE-2018-9311The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 thro...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now