2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7484 | — | — | 2.4% | Feb 26, 2018 | An issue was discovered in PureVPN through 5.19.4.0 on Windows. The client installation grants the Everyone group Full C... |
| CVE-2018-7480 | HIGH | 7.8 | 0.4% | Feb 25, 2018 | The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial... |
| CVE-2018-7476 | — | — | 0.9% | Feb 25, 2018 | controllers/admin/Linkage.php in dayrui FineCms 5.3.0 has Cross Site Scripting (XSS) via the id or lid parameter in a c=... |
| CVE-2018-7472 | — | — | 0.4% | Feb 25, 2018 | INVT Studio 1.2 allows remote attackers to cause a denial of service during import operations. |
| CVE-2018-7471 | — | — | 0.3% | Feb 25, 2018 | KingView 7.5SP1 has an integer overflow during stgopenstorage API read operations. |
| CVE-2018-7470 | — | — | 1.9% | Feb 25, 2018 | An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless function in coders/webp.c allows attackers ... |
| CVE-2018-7466 | — | — | 6.4% | Feb 25, 2018 | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging c... |
| CVE-2018-6883 | — | — | 1.3% | Feb 24, 2018 | Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an ... |
| CVE-2018-7456 | — | — | 3.1% | Feb 24, 2018 | A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.... |
| CVE-2018-7455 | — | — | 0.8% | Feb 24, 2018 | An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of servi... |
| CVE-2018-7454 | — | — | 0.8% | Feb 24, 2018 | A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of servic... |
| CVE-2018-7453 | — | — | 0.9% | Feb 24, 2018 | Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a... |
| CVE-2018-7452 | — | — | 0.8% | Feb 24, 2018 | A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of s... |
| CVE-2018-7434 | MEDIUM | 5.3 | 2.3% | Feb 24, 2018 | zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.... |
| CVE-2018-7447 | — | — | 0.7% | Feb 24, 2018 | mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sani... |
| CVE-2018-1305 | — | — | 15.0% | Feb 23, 2018 | Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 t... |
| CVE-2018-7443 | — | — | 3.3% | Feb 23, 2018 | The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image d... |
| CVE-2018-7421 | HIGH | 7.5 | 1.7% | Feb 23, 2018 | In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in... |
| CVE-2018-7420 | — | — | 2.8% | Feb 23, 2018 | In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could crash. This was addressed in wiretap/pcapn... |
| CVE-2018-7419 | — | — | 2.8% | Feb 23, 2018 | In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the NBAP dissector could crash. This was addressed in epan/dissectors/a... |
| CVE-2018-7418 | — | — | 2.8% | Feb 23, 2018 | In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissector... |
| CVE-2018-7417 | — | — | 2.7% | Feb 23, 2018 | In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the IPMI dissector could crash. This was addressed in epan/dissectors/p... |
| CVE-2018-7337 | — | — | 2.8% | Feb 23, 2018 | In Wireshark 2.4.0 to 2.4.4, the DOCSIS protocol dissector could crash. This was addressed in plugins/docsis/packet-docs... |
| CVE-2018-7336 | — | — | 2.8% | Feb 23, 2018 | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the FCP protocol dissector could crash. This was addressed in epan/diss... |
| CVE-2018-7335 | — | — | 2.8% | Feb 23, 2018 | In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the IEEE 802.11 dissector could crash. This was addressed in epan/crypt... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now