2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11017 | — | — | 1.4% | May 13, 2018 | The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size gr... |
| CVE-2018-10678 | — | — | 1.0% | May 13, 2018 | MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes i... |
| CVE-2018-11013 | — | — | 6.5% | May 13, 2018 | Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware vers... |
| CVE-2018-11012 | — | — | 0.6% | May 12, 2018 | ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController... |
| CVE-2018-11011 | — | — | 0.6% | May 12, 2018 | ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java. |
| CVE-2018-11004 | — | — | 0.6% | May 12, 2018 | An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/adm... |
| CVE-2018-11003 | — | — | 0.7% | May 12, 2018 | An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controll... |
| CVE-2018-10999 | — | — | 2.4% | May 12, 2018 | An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer ove... |
| CVE-2018-10998 | MEDIUM | 6.5 | 2.5% | May 12, 2018 | An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service... |
| CVE-2018-10996 | — | — | 5.4% | May 12, 2018 | The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or c... |
| CVE-2018-10992 | — | — | 1.5% | May 11, 2018 | lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWS... |
| CVE-2018-6619 | — | — | 0.4% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use... |
| CVE-2018-6618 | — | — | 0.5% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext pa... |
| CVE-2018-6617 | — | — | 0.4% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of a... |
| CVE-2018-6458 | — | — | 10.5% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attack... |
| CVE-2018-6362 | — | — | 1.1% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the P... |
| CVE-2018-6361 | — | — | 39.6% | May 11, 2018 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP acco... |
| CVE-2018-6023 | — | — | 2.4% | May 11, 2018 | Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi act... |
| CVE-2018-5304 | — | — | 0.8% | May 11, 2018 | An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vuln... |
| CVE-2018-5303 | — | — | 0.5% | May 11, 2018 | An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The license key parameter of the w... |
| CVE-2018-10832 | — | — | 6.0% | May 11, 2018 | ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations c... |
| CVE-2018-1280 | — | — | 2.2% | May 11, 2018 | Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenti... |
| CVE-2018-1278 | — | — | 1.3% | May 11, 2018 | Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x... |
| CVE-2018-1261 | MEDIUM | 4.7 | 1.3% | May 11, 2018 | Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved usin... |
| CVE-2018-1260 | — | — | 8.4% | May 11, 2018 | Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and olde... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now