2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20022 | — | — | 2.9% | Dec 19, 2018 | LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vul... |
| CVE-2018-20021 | — | — | 3.5% | Dec 19, 2018 | LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC cli... |
| CVE-2018-20020 | — | — | 8.6% | Dec 19, 2018 | LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside stru... |
| CVE-2018-15127 | — | — | 15.1% | Dec 19, 2018 | LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server c... |
| CVE-2018-15126 | — | — | 11.8% | Dec 19, 2018 | LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code ... |
| CVE-2018-17195 | — | — | 0.7% | Dec 19, 2018 | The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + ma... |
| CVE-2018-17194 | — | — | 3.0% | Dec 19, 2018 | When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Lengt... |
| CVE-2018-17193 | — | — | 2.8% | Dec 19, 2018 | The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resul... |
| CVE-2018-17192 | — | — | 2.7% | Dec 19, 2018 | The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing securi... |
| CVE-2018-20231 | — | — | 1.4% | Dec 19, 2018 | Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote atta... |
| CVE-2018-20230 | — | — | 0.8% | Dec 19, 2018 | An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in util... |
| CVE-2018-20228 | — | — | 0.4% | Dec 19, 2018 | Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF. |
| CVE-2018-19829 | — | — | 1.9% | Dec 18, 2018 | Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary ... |
| CVE-2018-19790 | — | — | 1.5% | Dec 18, 2018 | An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0... |
| CVE-2018-19789 | — | — | 3.6% | Dec 18, 2018 | An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1... |
| CVE-2018-18921 | — | — | 0.6% | Dec 18, 2018 | PHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action. |
| CVE-2018-6978 | — | — | 0.3% | Dec 18, 2018 | vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a ... |
| CVE-2018-20213 | — | — | 1.1% | Dec 18, 2018 | wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via... |
| CVE-2018-20201 | — | — | 1.1% | Dec 18, 2018 | There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a de... |
| CVE-2018-20198 | — | — | 1.2% | Dec 18, 2018 | A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA... |
| CVE-2018-20197 | — | — | 1.3% | Dec 18, 2018 | There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in F... |
| CVE-2018-20195 | — | — | 1.2% | Dec 18, 2018 | A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FA... |
| CVE-2018-20194 | — | — | 1.3% | Dec 18, 2018 | There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in F... |
| CVE-2018-7833 | — | — | 1.4% | Dec 17, 2018 | An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon ... |
| CVE-2018-7812 | — | — | 3.7% | Dec 17, 2018 | An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premiu... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now