2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-15840TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets...
CVE-2018-20378The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow r...
CVE-2018-6330Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.
CVE-2018-20678LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenti...
CVE-2018-20144GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorre...
CVE-2018-19648An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged u...
CVE-2018-3613Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially...
CVE-2018-15585Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject...
CVE-2018-14814WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation ...
CVE-2018-12183Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, in...
CVE-2018-12182Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalati...
CVE-2018-12181Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevat...
CVE-2018-12180Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of priv...
CVE-2018-12179Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of ...
CVE-2018-12178Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege an...
CVE-2018-19016Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and Compac...
CVE-2018-18994LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file...
CVE-2018-12551When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any mal...
CVE-2018-12550When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or...
CVE-2018-19466A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master passw...
CVE-2018-5927HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.
CVE-2018-5926A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process versio...
CVE-2018-5923In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution a...
CVE-2018-16207PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restricti...
CVE-2018-15817FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 v...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now