2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11231In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential info...
CVE-2018-10357A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to exe...
CVE-2018-10356A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker ...
CVE-2018-10355An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover ...
CVE-2018-10354A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a rem...
CVE-2018-10353A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote at...
CVE-2018-10352A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL state...
CVE-2018-10351A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL state...
CVE-2018-1193Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers...
CVE-2018-1310Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial...
CVE-2018-1309Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or...
CVE-2018-1125HIGH7.5procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FO...
CVE-2018-1123LOW3.9procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection ...
CVE-2018-1122HIGH7.3procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset...
CVE-2018-8176A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly valida...
CVE-2018-11396ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial ...
CVE-2018-1126MEDIUM4.8procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer...
CVE-2018-1124HIGH7.8procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec ...
CVE-2018-7295ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Messa...
CVE-2018-11334Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of...
CVE-2018-11362In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/diss...
CVE-2018-11361In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by a...
CVE-2018-11360In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epa...
CVE-2018-11359In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was ad...
CVE-2018-11358In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dis...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now