2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10172 | — | — | 0.4% | Apr 16, 2018 | 7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to... |
| CVE-2018-10170 | — | — | 2.5% | Apr 16, 2018 | NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" serv... |
| CVE-2018-10169 | — | — | 2.5% | Apr 16, 2018 | ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "ProtonVPN Service" ser... |
| CVE-2018-10070 | — | — | 13.0% | Apr 16, 2018 | A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU a... |
| CVE-2018-10138 | — | — | 0.7% | Apr 16, 2018 | The CATALooK.netStore module through 7.2.8 for DNN (formerly DotNetNuke) allows XSS via the /ViewEditGoogleMaps.aspx Por... |
| CVE-2018-10137 | — | — | 0.5% | Apr 16, 2018 | iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&... |
| CVE-2018-10136 | — | — | 0.7% | Apr 16, 2018 | iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?s... |
| CVE-2018-10135 | — | — | 0.7% | Apr 16, 2018 | iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. |
| CVE-2018-0737 | — | — | 12.0% | Apr 16, 2018 | The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attac... |
| CVE-2018-3849 | HIGH | 8.8 | 4.0% | Apr 16, 2018 | In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buf... |
| CVE-2018-3848 | HIGH | 8.8 | 3.9% | Apr 16, 2018 | In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buf... |
| CVE-2018-3846 | HIGH | 8.8 | 3.1% | Apr 16, 2018 | In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a sta... |
| CVE-2018-10133 | — | — | 1.4% | Apr 16, 2018 | PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, relate... |
| CVE-2018-10132 | — | — | 0.5% | Apr 16, 2018 | PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injec... |
| CVE-2018-10128 | — | — | 0.7% | Apr 16, 2018 | An issue was discovered in XYHCMS 3.5. It has XSS via the test parameter to index.php. |
| CVE-2018-10127 | — | — | 0.5% | Apr 16, 2018 | An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addi... |
| CVE-2018-5382 | MEDIUM | 4.4 | 0.3% | Apr 16, 2018 | The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity ... |
| CVE-2018-10124 | — | — | 0.6% | Apr 16, 2018 | The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture an... |
| CVE-2018-0562 | — | — | 1.1% | Apr 16, 2018 | Untrusted search path vulnerability in Installer of SoundEngine Free ver.5.21 and earlier allows an attacker to gain pri... |
| CVE-2018-0561 | — | — | 1.1% | Apr 16, 2018 | Untrusted search path vulnerability in The installer of PhishWall Client Internet Explorer edition Ver. 3.7.15 and earli... |
| CVE-2018-0560 | — | — | 1.0% | Apr 16, 2018 | Hatena Bookmark App for iOS Version 3.0 to 3.70 allows remote attackers to spoof the address bar via vectors related to ... |
| CVE-2018-0551 | — | — | 0.7% | Apr 16, 2018 | Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbit... |
| CVE-2018-0550 | — | — | 1.0% | Apr 16, 2018 | Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title... |
| CVE-2018-0549 | — | — | 0.7% | Apr 16, 2018 | Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbit... |
| CVE-2018-0548 | — | — | 1.3% | Apr 16, 2018 | Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now