2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11357In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive ...
CVE-2018-11356In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/disse...
CVE-2018-11355In Wireshark 2.6.0, the RTCP dissector could crash. This was addressed in epan/dissectors/packet-rtcp.c by avoiding a bu...
CVE-2018-11354In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by m...
CVE-2018-9019CRITICAL9.8SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands v...
CVE-2018-10095Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script...
CVE-2018-10094SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto...
CVE-2018-10092The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging suppor...
CVE-2018-6493HIGH8.8SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation,...
CVE-2018-6492MEDIUM4.7Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version...
CVE-2018-11384The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds rea...
CVE-2018-11383The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and app...
CVE-2018-11382The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bound...
CVE-2018-11381The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-o...
CVE-2018-11380The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of...
CVE-2018-11379The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-b...
CVE-2018-11378The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM fil...
CVE-2018-11377The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-b...
CVE-2018-11376The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-boun...
CVE-2018-11375The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bound...
CVE-2018-6494MEDIUM5.4Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,...
CVE-2018-11093MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inj...
CVE-2018-11373iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
CVE-2018-11372iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
CVE-2018-11371SkyCaiji 1.2 allows CSRF to add an Administrator user.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now