2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20369 | — | — | 0.7% | Dec 23, 2018 | Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi... |
| CVE-2018-20368 | — | — | 0.6% | Dec 23, 2018 | The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the M... |
| CVE-2018-20331 | — | — | 0.6% | Dec 23, 2018 | Local attackers can trigger a Kernel Pool Buffer Overflow in Antiy AVL ATool v1.0.0.22. An attacker must first obtain th... |
| CVE-2018-20367 | — | — | 0.7% | Dec 22, 2018 | The "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consu... |
| CVE-2018-20365 | — | — | 2.8% | Dec 22, 2018 | LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow. |
| CVE-2018-20364 | — | — | 2.6% | Dec 22, 2018 | LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference. |
| CVE-2018-20363 | — | — | 2.8% | Dec 22, 2018 | LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference. |
| CVE-2018-20362 | — | — | 1.2% | Dec 22, 2018 | A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA... |
| CVE-2018-20361 | — | — | 1.2% | Dec 22, 2018 | An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Adva... |
| CVE-2018-20359 | — | — | 1.2% | Dec 22, 2018 | An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec.c in Free... |
| CVE-2018-20358 | — | — | 1.2% | Dec 22, 2018 | An invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict.c in Freeware A... |
| CVE-2018-20357 | — | — | 1.2% | Dec 22, 2018 | A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder... |
| CVE-2018-19863 | — | — | 0.4% | Dec 22, 2018 | An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in ins... |
| CVE-2018-20351 | — | — | 0.6% | Dec 22, 2018 | The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832. |
| CVE-2018-20349 | — | — | 1.6% | Dec 22, 2018 | The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attac... |
| CVE-2018-20348 | — | — | 0.4% | Dec 22, 2018 | libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a de... |
| CVE-2018-20325 | — | — | 3.4% | Dec 21, 2018 | There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python.... |
| CVE-2018-20322 | — | — | 1.1% | Dec 21, 2018 | LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting i... |
| CVE-2018-20226 | — | — | 1.7% | Dec 21, 2018 | An organization administrator can add a super administrator in THEHIVE PROJECT Cortex before 2.1.3 due to the lack of ov... |
| CVE-2018-20193 | — | — | 1.3% | Dec 21, 2018 | Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by... |
| CVE-2018-18008 | — | — | 2.0% | Dec 21, 2018 | spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credenti... |
| CVE-2018-16778 | — | — | 0.8% | Dec 21, 2018 | Cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0 allows remote attackers to inject arbitrary we... |
| CVE-2018-20346 | — | — | 9.7% | Dec 21, 2018 | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow)... |
| CVE-2018-20345 | — | — | 0.7% | Dec 21, 2018 | Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attack... |
| CVE-2018-20342 | — | — | 0.6% | Dec 21, 2018 | The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This all... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now