2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7804 | — | — | 0.9% | Dec 17, 2018 | A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quant... |
| CVE-2018-7797 | — | — | 0.8% | Dec 17, 2018 | A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure ... |
| CVE-2018-11795 | — | — | — | Dec 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-20190 | — | — | 2.6% | Dec 17, 2018 | In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Eval::operator()(Sass::Supports_Operator*) in eval.cp... |
| CVE-2018-20189 | — | — | 2.3% | Dec 17, 2018 | In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of s... |
| CVE-2018-20188 | — | — | 0.5% | Dec 17, 2018 | FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account. |
| CVE-2018-20186 | — | — | 1.2% | Dec 17, 2018 | An issue was discovered in Bento4 1.5.1-627. AP4_Sample::ReadData in Core/Ap4Sample.cpp allows attackers to trigger an a... |
| CVE-2018-20184 | — | — | 2.3% | Dec 17, 2018 | In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c... |
| CVE-2018-20133 | — | — | 1.8% | Dec 17, 2018 | ymlref allows code injection. |
| CVE-2018-20092 | — | — | 2.2% | Dec 17, 2018 | PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request. |
| CVE-2018-19976 | — | — | 1.3% | Dec 17, 2018 | In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara... |
| CVE-2018-19975 | — | — | 1.4% | Dec 17, 2018 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in liby... |
| CVE-2018-19974 | — | — | 1.3% | Dec 17, 2018 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libya... |
| CVE-2018-19936 | — | — | 1.1% | Dec 17, 2018 | PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion. |
| CVE-2018-19933 | — | — | 3.5% | Dec 17, 2018 | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and Ne... |
| CVE-2018-19828 | — | — | 2.3% | Dec 17, 2018 | Artica Integria IMS 5.0.83 has XSS via the search_string parameter. |
| CVE-2018-19036 | — | — | 2.4% | Dec 17, 2018 | An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could pote... |
| CVE-2018-18555 | — | — | 1.8% | Dec 17, 2018 | A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to adm... |
| CVE-2018-16596 | — | — | 0.7% | Dec 17, 2018 | A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, an... |
| CVE-2018-14856 | — | — | 0.9% | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-... |
| CVE-2018-14855 | — | — | 0.9% | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-F... |
| CVE-2018-14854 | — | — | 0.9% | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-... |
| CVE-2018-14853 | — | — | 0.9% | Dec 17, 2018 | A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4... |
| CVE-2018-14852 | — | — | 1.0% | Dec 17, 2018 | Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver... |
| CVE-2018-20172 | — | — | 1.6% | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbo... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now