2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18341 | — | — | 1.5% | Dec 11, 2018 | An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote a... |
| CVE-2018-18340 | — | — | 1.4% | Dec 11, 2018 | Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentia... |
| CVE-2018-18339 | — | — | 1.4% | Dec 11, 2018 | Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially e... |
| CVE-2018-18338 | — | — | 1.4% | Dec 11, 2018 | Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to po... |
| CVE-2018-18337 | — | — | 1.7% | Dec 11, 2018 | Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a ... |
| CVE-2018-18336 | — | — | 1.5% | Dec 11, 2018 | Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exp... |
| CVE-2018-18335 | — | — | 3.7% | Dec 11, 2018 | Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit hea... |
| CVE-2018-17481 | — | — | 1.6% | Dec 11, 2018 | Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potent... |
| CVE-2018-20059 | — | — | 1.5% | Dec 11, 2018 | jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE. |
| CVE-2018-20058 | — | — | 1.4% | Dec 11, 2018 | In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-2863... |
| CVE-2018-20057 | — | — | 7.4% | Dec 11, 2018 | An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd... |
| CVE-2018-20056 | — | — | 7.0% | Dec 11, 2018 | An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-... |
| CVE-2018-20051 | — | — | 1.4% | Dec 10, 2018 | Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of... |
| CVE-2018-20050 | — | — | 1.5% | Dec 10, 2018 | Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause... |
| CVE-2018-15757 | — | — | — | Dec 10, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-16636 | — | — | 1.0% | Dec 10, 2018 | Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. |
| CVE-2018-16635 | — | — | 0.6% | Dec 10, 2018 | Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. |
| CVE-2018-15805 | — | — | 1.6% | Dec 10, 2018 | Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an att... |
| CVE-2018-1671 | — | — | 1.7% | Dec 10, 2018 | IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML... |
| CVE-2018-1000866 | — | — | 1.6% | Dec 10, 2018 | A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/ko... |
| CVE-2018-1000865 | — | — | 1.6% | Dec 10, 2018 | A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/koh... |
| CVE-2018-1000864 | — | — | 2.8% | Dec 10, 2018 | A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allo... |
| CVE-2018-1000863 | — | — | 6.8% | Dec 10, 2018 | A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.... |
| CVE-2018-1000862 | — | — | 1.4% | Dec 10, 2018 | An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSu... |
| CVE-2018-20018 | — | — | 1.2% | Dec 10, 2018 | S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now