2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5202 | — | — | 1.5% | Dec 21, 2018 | SKCertService 2.5.5 and earlier contains a vulnerability that could allow remote attacker to execute arbitrary code. Thi... |
| CVE-2018-5201 | — | — | 0.7% | Dec 21, 2018 | Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and... |
| CVE-2018-18332 | — | — | 1.4% | Dec 21, 2018 | A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissi... |
| CVE-2018-18331 | — | — | 1.4% | Dec 21, 2018 | A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow ... |
| CVE-2018-18330 | — | — | 1.0% | Dec 21, 2018 | An Address Bar Spoofing vulnerability in Trend Micro Dr. Safety for Android (Consumer) versions 3.0.1324 and below could... |
| CVE-2018-11794 | — | — | — | Dec 21, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-20339 | — | — | 2.4% | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. |
| CVE-2018-20338 | — | — | 11.5% | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. |
| CVE-2018-20337 | — | — | 2.1% | Dec 21, 2018 | There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted inp... |
| CVE-2018-20332 | — | — | 2.2% | Dec 21, 2018 | An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files... |
| CVE-2018-20330 | — | — | 2.0% | Dec 21, 2018 | The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via ... |
| CVE-2018-20329 | — | — | 1.2% | Dec 21, 2018 | Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users wit... |
| CVE-2018-20328 | — | — | 0.7% | Dec 21, 2018 | Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated ... |
| CVE-2018-20327 | — | — | 0.6% | Dec 21, 2018 | Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies ... |
| CVE-2018-20318 | — | — | 1.7% | Dec 21, 2018 | An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWx... |
| CVE-2018-19242 | — | — | 2.9% | Dec 20, 2018 | Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32 and TEW-673GRU devices allows attackers to hijack the contr... |
| CVE-2018-19241 | — | — | 2.3% | Dec 20, 2018 | Buffer overflow in video.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.... |
| CVE-2018-19240 | — | — | 3.7% | Dec 20, 2018 | Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.... |
| CVE-2018-19239 | — | — | 5.1% | Dec 20, 2018 | TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the tim... |
| CVE-2018-19134 | — | — | 2.9% | Dec 20, 2018 | In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafte... |
| CVE-2018-18767 | — | — | 0.6% | Dec 20, 2018 | An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g.,... |
| CVE-2018-18629 | — | — | 1.5% | Dec 20, 2018 | An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search pa... |
| CVE-2018-18442 | — | — | 1.3% | Dec 20, 2018 | D-Link DCS-825L devices with firmware 1.08 do not employ a suitable mechanism to prevent denial-of-service (DoS) attacks... |
| CVE-2018-18441 | — | — | 1.9% | Dec 20, 2018 | D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices in... |
| CVE-2018-18399 | — | — | 2.8% | Dec 20, 2018 | SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 all... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now