2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1000115Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln...
CVE-2018-7668TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachment...
CVE-2018-7667Adminer through 4.3.1 has SSRF via the server parameter.
CVE-2018-7666An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote...
CVE-2018-7665An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter...
CVE-2018-7664An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacter...
CVE-2018-7663An issue was discovered in resources/views/layouts/app.blade.php in Voten.co before 2017-08-25. An unescaped template li...
CVE-2018-7662Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.fun...
CVE-2018-7661Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests...
CVE-2018-7567In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenti...
CVE-2018-7560HIGH7.5index.js in the Anton Myshenin aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of S...
CVE-2018-7653In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
CVE-2018-7654On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access t...
CVE-2018-7652MEDIUM6.1lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS.
CVE-2018-7651index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in...
CVE-2018-7583Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500.
CVE-2018-7449SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in...
CVE-2018-7433The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
CVE-2018-1373HIGH7.5IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a r...
CVE-2018-7648CRITICAL9.8An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which ...
CVE-2018-7643The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (...
CVE-2018-7642The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GN...
CVE-2018-1063Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity...
CVE-2018-1058HIGH8.8A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker wit...
CVE-2018-7641An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now