2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18989 | — | — | 1.6% | Dec 4, 2018 | In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when ... |
| CVE-2018-18991 | — | — | 0.9% | Dec 4, 2018 | Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker... |
| CVE-2018-17160 | — | — | 3.3% | Dec 4, 2018 | In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models pro... |
| CVE-2018-5496 | — | — | 0.4% | Dec 4, 2018 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P2 are susceptible to a vulnerability which discloses sensitive in... |
| CVE-2018-7987 | — | — | 0.7% | Dec 4, 2018 | There is an out-of-bounds write vulnerability on Huawei P20 smartphones with versions before 8.1.0.171(C00). The softwar... |
| CVE-2018-7956 | — | — | 0.8% | Dec 4, 2018 | Huawei VIP App is a mobile app for Malaysia customers that purchased P20 Series, Nova 3/3i and Mate 20. There is a vulne... |
| CVE-2018-0468 | — | — | 0.3% | Dec 4, 2018 | A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) c... |
| CVE-2018-6152 | — | — | 1.3% | Dec 4, 2018 | The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of f... |
| CVE-2018-6116 | — | — | 1.4% | Dec 4, 2018 | A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially pe... |
| CVE-2018-6115 | — | — | 1.1% | Dec 4, 2018 | Inappropriate setting of the SEE_MASK_FLAG_NO_UI flag in file downloads in Google Chrome prior to 66.0.3359.117 allowed ... |
| CVE-2018-6108 | — | — | 1.4% | Dec 4, 2018 | Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote at... |
| CVE-2018-6107 | — | — | 1.4% | Dec 4, 2018 | Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote at... |
| CVE-2018-6105 | — | — | 1.3% | Dec 4, 2018 | Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker... |
| CVE-2018-6104 | — | — | 1.4% | Dec 4, 2018 | Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote at... |
| CVE-2018-6103 | — | — | 1.5% | Dec 4, 2018 | A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass perm... |
| CVE-2018-6102 | — | — | 1.2% | Dec 4, 2018 | Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker ... |
| CVE-2018-6101 | — | — | 2.7% | Dec 4, 2018 | A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbit... |
| CVE-2018-6099 | — | — | 1.6% | Dec 4, 2018 | A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-o... |
| CVE-2018-6098 | — | — | 1.4% | Dec 4, 2018 | Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote at... |
| CVE-2018-6095 | — | — | 1.6% | Dec 4, 2018 | Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a rem... |
| CVE-2018-6094 | — | — | 1.6% | Dec 4, 2018 | Inline metadata in GarbageCollection in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially ex... |
| CVE-2018-6092 | — | — | 9.2% | Dec 4, 2018 | An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker t... |
| CVE-2018-6090 | — | — | 3.3% | Dec 4, 2018 | An integer overflow that lead to a heap buffer-overflow in Skia in Google Chrome prior to 66.0.3359.117 allowed a remote... |
| CVE-2018-6089 | — | — | 1.6% | Dec 4, 2018 | A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior... |
| CVE-2018-6088 | — | — | 2.4% | Dec 4, 2018 | An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now