2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-20316HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can ca...
CVE-2018-20315HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-ba...
CVE-2018-20314HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that ca...
CVE-2018-20313HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that c...
CVE-2018-20312HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can ca...
CVE-2018-20311HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can ...
CVE-2018-20310HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can ca...
CVE-2018-20309HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that c...
CVE-2018-19418HIGH7.8Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security perm...
CVE-2018-25002HIGH8.8uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-201...
CVE-2018-19944HIGH7.5A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If expl...
CVE-2018-19941HIGH7.5A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sens...
CVE-2018-16795HIGH8.8OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of...
CVE-2018-1000893HIGH7.5Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.
CVE-2018-1000892HIGH7.5Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.
CVE-2018-1000891HIGH7.5Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.
CVE-2018-7580HIGH7.5Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hu...
CVE-2018-16723HIGH7.8In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) o...
CVE-2018-16722HIGH7.8In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) o...
CVE-2018-16721HIGH7.8In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) o...
CVE-2018-16720HIGH7.8In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) o...
CVE-2018-16719HIGH7.8In Jingyun Antivirus v2.4.2.39, the driver file (hookbody.sys) allows local users to cause a denial of service (BSOD) or...
CVE-2018-19952HIGH7.5If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issu...
CVE-2018-4474HIGH7.5A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, w...
CVE-2018-4467HIGH7.8A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.3, Sec...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now