2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1049 | MEDIUM | 5.9 | 7.3% | Feb 16, 2018 | In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from ke... |
| CVE-2018-7188 | — | — | 0.5% | Feb 16, 2018 | An XSS vulnerability (via an SVG image) in Tiki before 18 allows an authenticated user to gain administrator privileges ... |
| CVE-2018-7187 | HIGH | 8.8 | 63.2% | Feb 16, 2018 | The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import pa... |
| CVE-2018-0516 | — | — | 0.9% | Feb 16, 2018 | Untrusted search path vulnerability in FLET'S v4 / v6 address selection tool allows an attacker to gain privileges via a... |
| CVE-2018-0515 | — | — | 0.9% | Feb 16, 2018 | Untrusted search path vulnerability in "FLET'S Azukeru Backup Tool" version 1.5.2.6 and earlier allows an attacker to ga... |
| CVE-2018-7186 | — | — | 3.5% | Feb 16, 2018 | Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allow... |
| CVE-2018-6944 | — | — | 1.2% | Feb 16, 2018 | core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerabili... |
| CVE-2018-6943 | — | — | 1.1% | Feb 16, 2018 | core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerabil... |
| CVE-2018-1000066 | — | — | — | Feb 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5380. Reason: This candidate is a reservation du... |
| CVE-2018-1000065 | — | — | — | Feb 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5381. Reason: This candidate is a reservation du... |
| CVE-2018-1000064 | — | — | — | Feb 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5378. Reason: This candidate is a reservation du... |
| CVE-2018-1000063 | — | — | — | Feb 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5379. Reason: This candidate is a reservation du... |
| CVE-2018-7176 | — | — | 2.4% | Feb 16, 2018 | FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add u... |
| CVE-2018-6324 | — | — | 0.9% | Feb 16, 2018 | F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upo... |
| CVE-2018-6189 | — | — | 0.9% | Feb 16, 2018 | F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body... |
| CVE-2018-1000068 | MEDIUM | 5.3 | 2.0% | Feb 16, 2018 | An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, tha... |
| CVE-2018-1000067 | MEDIUM | 5.3 | 1.7% | Feb 16, 2018 | An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that a... |
| CVE-2018-6316 | — | — | 1.9% | Feb 15, 2018 | Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authe... |
| CVE-2018-5767 | — | — | 41.4% | Feb 15, 2018 | An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code... |
| CVE-2018-7175 | — | — | 0.8% | Feb 15, 2018 | An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of... |
| CVE-2018-7174 | — | — | 0.8% | Feb 15, 2018 | An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service becau... |
| CVE-2018-7173 | — | — | 0.8% | Feb 15, 2018 | A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific... |
| CVE-2018-7169 | — | — | 1.6% | Feb 15, 2018 | An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be place... |
| CVE-2018-7054 | — | — | 2.4% | Feb 15, 2018 | An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconn... |
| CVE-2018-7053 | — | — | 2.5% | Feb 15, 2018 | An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are r... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now