2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-7816A Permissions, Privileges, and Access Control vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhan...
CVE-2018-12886stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 thro...
CVE-2018-7202An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.
CVE-2018-14729The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to ex...
CVE-2018-12270In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the clie...
CVE-2018-3701Improper directory permissions in the installer for Intel(R) PROSet/Wireless WiFi Software version 20.100 and earlier ma...
CVE-2018-20500An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13...
CVE-2018-19585GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection...
CVE-2018-17181An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/p...
CVE-2018-17180An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/downloa...
CVE-2018-17179An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/...
CVE-2018-7191In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. Thi...
CVE-2018-20007Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical at...
CVE-2018-12556The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn relea...
CVE-2018-17048admin/Lib/Action/FpluginAction.class.php in FDCMS (aka Fangfa Content Manage System) 4.2 allows SQL Injection.
CVE-2018-16656DoBox_CstmBox_Info.model.htm on Kyocera TASKalfa 4002i and 6002i devices allows remote attackers to read the documents o...
CVE-2018-8940ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external ...
CVE-2018-6885An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10....
CVE-2018-11691Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change th...
CVE-2018-18800The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=...
CVE-2018-16138An issue was discovered in the administration page in IPBRICK OS 6.3. There are multiple XSS vulnerabilities.
CVE-2018-16137An issue was discovered in the Web Management Console in IPBRICK OS 6.3. There are multiple SQL injections.
CVE-2018-16136An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF to...
CVE-2018-18912An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs wh...
CVE-2018-16139Cross-site scripting (XSS) vulnerability in BIBLIOsoft BIBLIOpac 2008 allows remote attackers to inject arbitrary web sc...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now