2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-8756Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary cod...
CVE-2018-8754MEDIUM5.5The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly c...
CVE-2018-8741A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete)...
CVE-2018-8737Bookme Control Panel 2.0 Application is vulnerable to stored XSS within the Customers "Book Me" function. Within the Nam...
CVE-2018-8740In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL point...
CVE-2018-3561In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race c...
CVE-2018-3560In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Double...
CVE-2018-1200Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) ...
CVE-2018-1199MEDIUM5.3Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4....
CVE-2018-1078OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffi...
CVE-2018-8739VPN Unlimited 4.2.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. The ...
CVE-2018-1068MEDIUM6.7A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privi...
CVE-2018-7544A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interfac...
CVE-2018-1000134UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d2136789...
CVE-2018-1000133Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that...
CVE-2018-1324MEDIUM5.5A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field par...
CVE-2018-5476HIGH7.8A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.0...
CVE-2018-7033SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
CVE-2018-1319In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a mali...
CVE-2018-6957VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulner...
CVE-2018-6231A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) ...
CVE-2018-6230A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an ...
CVE-2018-6229A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker ...
CVE-2018-6228A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to exe...
CVE-2018-6227A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now