2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-25081HIGH7.5Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position i...
CVE-2018-25079HIGH7.5A vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is s...
CVE-2018-25078HIGH7.8man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /...
CVE-2018-25077HIGH7.5A vulnerability was found in melnaron mel-spintax. It has been rated as problematic. Affected by this issue is some unkn...
CVE-2018-25074HIGH7.5A vulnerability was found in Prestaul skeemas and classified as problematic. This issue affects some unknown processing ...
CVE-2018-25067HIGH7.2A vulnerability, which was classified as critical, was found in JoomGallery up to 3.3.3. This affects an unknown part of...
CVE-2018-25062HIGH7.5A vulnerability classified as problematic has been found in flar2 ElementalX up to 6.x on Nexus 9. Affected is the funct...
CVE-2018-25061HIGH7.5A vulnerability was found in rgb2hex up to 0.1.5. It has been rated as problematic. This issue affects some unknown proc...
CVE-2018-25060HIGH7.5A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown function...
CVE-2018-25049HIGH7.5A vulnerability was found in email-existence. It has been rated as problematic. Affected by this issue is some unknown f...
CVE-2018-25044HIGH8.8A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processin...
CVE-2018-25043HIGH8.8A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component P...
CVE-2018-25042HIGH8.8A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads ...
CVE-2018-25041HIGH8.8A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionali...
CVE-2018-25040HIGH8.8A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknow...
CVE-2018-18907HIGH7.5An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaini...
CVE-2018-17240HIGH7.5There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacke...
CVE-2018-25033HIGH8.1ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenera...
CVE-2018-25032HIGH7.5zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche...
CVE-2018-25029HIGH8.1The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an a...
CVE-2018-17875HIGH8.8A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users...
CVE-2018-25028HIGH7.5An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_context can cause a use-after-free.
CVE-2018-25027HIGH7.5An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_format_info can cause a use-after-free.
CVE-2018-25023HIGH7.5An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, ...
CVE-2018-4302HIGH7.8A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iClou...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now