2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-4197A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS...
CVE-2018-4195An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to...
CVE-2018-4191A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12,...
CVE-2018-4178A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved ...
CVE-2018-4153An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
CVE-2018-4145Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO...
CVE-2018-4126A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, mac...
CVE-2018-20506SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow)...
CVE-2018-20505SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial o...
CVE-2018-1936HIGH8.4IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds...
CVE-2018-1913MEDIUM5.4IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This ...
CVE-2018-1731MEDIUM4.8IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This ...
CVE-2018-18035A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to co...
CVE-2018-12680The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a ...
CVE-2018-12679The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of serv...
CVE-2018-19275The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, whic...
CVE-2018-15180qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.
CVE-2018-4053MEDIUM5.5An exploitable local denial-of-service vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version...
CVE-2018-4052MEDIUM5.5An exploitable local information leak vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version ...
CVE-2018-4051MEDIUM5.5An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, vers...
CVE-2018-4049HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” dir...
CVE-2018-3974HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install dir...
CVE-2018-1917LOW3.5IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an authenticated user to access JSP files and disclos...
CVE-2018-1906MEDIUM4.3IBM InfoSphere Information Server 11.3, 11.5, and 11.7could allow an authenticated user to download code using a special...
CVE-2018-1874MEDIUM4.6IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access t...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now