2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11357 | — | — | 2.9% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive ... |
| CVE-2018-11356 | — | — | 2.9% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/disse... |
| CVE-2018-11355 | — | — | 3.2% | May 22, 2018 | In Wireshark 2.6.0, the RTCP dissector could crash. This was addressed in epan/dissectors/packet-rtcp.c by avoiding a bu... |
| CVE-2018-11354 | — | — | 2.8% | May 22, 2018 | In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by m... |
| CVE-2018-9019 | CRITICAL | 9.8 | 4.0% | May 22, 2018 | SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2018-10095 | — | — | 87.0% | May 22, 2018 | Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script... |
| CVE-2018-10094 | — | — | 71.2% | May 22, 2018 | SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto... |
| CVE-2018-10092 | — | — | 2.0% | May 22, 2018 | The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging suppor... |
| CVE-2018-6493 | HIGH | 8.8 | 2.0% | May 22, 2018 | SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation,... |
| CVE-2018-6492 | MEDIUM | 4.7 | 1.6% | May 22, 2018 | Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version... |
| CVE-2018-11384 | — | — | 1.1% | May 22, 2018 | The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds rea... |
| CVE-2018-11383 | — | — | 1.1% | May 22, 2018 | The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and app... |
| CVE-2018-11382 | — | — | 1.1% | May 22, 2018 | The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bound... |
| CVE-2018-11381 | — | — | 1.1% | May 22, 2018 | The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-o... |
| CVE-2018-11380 | — | — | 1.1% | May 22, 2018 | The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of... |
| CVE-2018-11379 | — | — | 1.2% | May 22, 2018 | The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-b... |
| CVE-2018-11378 | — | — | 1.1% | May 22, 2018 | The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM fil... |
| CVE-2018-11377 | — | — | 1.4% | May 22, 2018 | The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-b... |
| CVE-2018-11376 | — | — | 1.1% | May 22, 2018 | The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-boun... |
| CVE-2018-11375 | — | — | 1.1% | May 22, 2018 | The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bound... |
| CVE-2018-6494 | MEDIUM | 5.4 | 1.2% | May 22, 2018 | Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,... |
| CVE-2018-11093 | MEDIUM | 6.1 | 1.0% | May 22, 2018 | Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inj... |
| CVE-2018-11373 | — | — | 1.2% | May 22, 2018 | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. |
| CVE-2018-11372 | — | — | 1.2% | May 22, 2018 | iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter. |
| CVE-2018-11371 | — | — | 0.7% | May 22, 2018 | SkyCaiji 1.2 allows CSRF to add an Administrator user. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now