2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11438 | — | — | 2.7% | May 30, 2018 | The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution... |
| CVE-2018-11437 | — | — | 1.4% | May 30, 2018 | The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclos... |
| CVE-2018-11436 | — | — | 1.4% | May 30, 2018 | The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-base... |
| CVE-2018-11435 | — | — | 1.4% | May 30, 2018 | The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause informati... |
| CVE-2018-11434 | — | — | 1.4% | May 30, 2018 | The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap... |
| CVE-2018-11433 | — | — | 1.4% | May 30, 2018 | The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclo... |
| CVE-2018-11432 | — | — | 1.4% | May 30, 2018 | The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (hea... |
| CVE-2018-11559 | — | — | 0.7% | May 30, 2018 | DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter. |
| CVE-2018-11558 | — | — | 0.7% | May 30, 2018 | DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter. |
| CVE-2018-11557 | — | — | 0.6% | May 30, 2018 | YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter. |
| CVE-2018-11556 | — | — | 1.1% | May 30, 2018 | tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in lib... |
| CVE-2018-11555 | — | — | 1.1% | May 30, 2018 | tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a... |
| CVE-2018-11550 | — | — | — | May 30, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9850. Reason: This candidate is a reservation ... |
| CVE-2018-11235 | — | — | 49.2% | May 30, 2018 | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote... |
| CVE-2018-11233 | — | — | 4.3% | May 30, 2018 | In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code t... |
| CVE-2018-11549 | — | — | 0.7% | May 29, 2018 | An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> ... |
| CVE-2018-11548 | — | — | 1.3% | May 29, 2018 | An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connectio... |
| CVE-2018-11547 | — | — | 1.6% | May 29, 2018 | md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandl... |
| CVE-2018-11546 | — | — | 1.6% | May 29, 2018 | md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error. |
| CVE-2018-11545 | — | — | 1.6% | May 29, 2018 | md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link lab... |
| CVE-2018-11544 | CRITICAL | 9.8 | 1.5% | May 29, 2018 | The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are sto... |
| CVE-2018-10755 | — | — | — | May 29, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is not about any specific pr... |
| CVE-2018-6964 | — | — | 0.4% | May 29, 2018 | VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to ... |
| CVE-2018-3745 | CRITICAL | 9.1 | 2.2% | May 29, 2018 | atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below. |
| CVE-2018-3744 | CRITICAL | 9.8 | 2.3% | May 29, 2018 | The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the s... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now