2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20433 | — | — | 4.5% | Dec 24, 2018 | c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during ini... |
| CVE-2018-19357 | — | — | 3.1% | Dec 24, 2018 | XMPlay 3.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow... |
| CVE-2018-20431 | — | — | 2.2% | Dec 24, 2018 | GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/... |
| CVE-2018-20430 | — | — | 2.2% | Dec 24, 2018 | GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_e... |
| CVE-2018-20429 | — | — | 1.5% | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability ... |
| CVE-2018-20428 | — | — | 1.5% | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerabilit... |
| CVE-2018-20427 | — | — | 1.3% | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability t... |
| CVE-2018-20426 | — | — | 1.5% | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability ... |
| CVE-2018-20425 | — | — | 1.5% | Dec 24, 2018 | libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file. |
| CVE-2018-20424 | — | — | 0.9% | Dec 24, 2018 | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data str... |
| CVE-2018-20423 | — | — | 1.2% | Dec 24, 2018 | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting b... |
| CVE-2018-20422 | — | — | 1.3% | Dec 24, 2018 | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-... |
| CVE-2018-20418 | — | — | 3.7% | Dec 24, 2018 | index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. |
| CVE-2018-20421 | — | — | 1.5% | Dec 24, 2018 | Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length... |
| CVE-2018-20420 | — | — | 1.0% | Dec 24, 2018 | In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .s... |
| CVE-2018-20419 | — | — | 0.5% | Dec 24, 2018 | DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account. |
| CVE-2018-20410 | — | — | 1.6% | Dec 24, 2018 | WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow. The vulnerability is triggered when sendin... |
| CVE-2018-20409 | — | — | 1.1% | Dec 23, 2018 | An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4A... |
| CVE-2018-20408 | — | — | 1.2% | Dec 23, 2018 | An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4... |
| CVE-2018-20407 | — | — | 1.2% | Dec 23, 2018 | An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream... |
| CVE-2018-20406 | — | — | 5.8% | Dec 23, 2018 | Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during... |
| CVE-2018-20402 | — | — | 1.0% | Dec 23, 2018 | Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial adminis... |
| CVE-2018-20401 | — | — | 1.5% | Dec 23, 2018 | Zoom 5352 v5.5.8.6Y devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and is... |
| CVE-2018-20400 | — | — | 1.5% | Dec 23, 2018 | Ubee DVW2108 6.28.1017 and DVW2110 6.28.2012 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.44... |
| CVE-2018-20399 | — | — | 2.6% | Dec 23, 2018 | Motorola SBG901 SBG901-2.10.1.1-GA-00-581-NOSH, SBG941 SBG941-2.11.0.0-GA-07-624-NOSH, and SVG1202 SVG1202-2.1.0.0-GA-14... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now