2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1262Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation ac...
CVE-2018-11094An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/Rebo...
CVE-2018-11127e107 2.1.7 has CSRF resulting in arbitrary user deletion.
CVE-2018-11126dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.
CVE-2018-11125Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-1087HIGH8kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnera...
CVE-2018-11105There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka ...
CVE-2018-3661Buffer overflow in Intel system Configuration utilities selview.exe and syscfg.exe before version 14 build 11 allows a l...
CVE-2018-3634MEDIUM5.5Parameter corruption in NDIS filter driver in Intel Online Connect Access 1.9.22.0 allows an attacker to cause a denial ...
CVE-2018-3611Bounds check vulnerability in User Mode Driver in Intel Graphics Driver 15.40.x.4 and 21.20.x.x allows unprivileged user...
CVE-2018-1131Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurat...
CVE-2018-10825Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turt...
CVE-2018-11102An issue was discovered in Libav 12.3. A read access violation in the mov_probe function in libavformat/mov.c allows rem...
CVE-2018-11100The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a fi...
CVE-2018-11098An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/uplo...
CVE-2018-11097An issue was discovered in cloudwu/cstring through 2016-11-09. There is a memory leak vulnerability that could lead to a...
CVE-2018-11095The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file si...
CVE-2018-11091CRITICAL9.9An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. I...
CVE-2018-11090An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker t...
CVE-2018-10994js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
CVE-2018-8843Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing speci...
CVE-2018-10991Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10990. Reason: This candidate is a reservation...
CVE-2018-10990HIGH8On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state ...
CVE-2018-10989MEDIUM6.6Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "pa...
CVE-2018-10252An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely ge...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now