2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19748 | — | — | 2.0% | Nov 29, 2018 | app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=... |
| CVE-2018-19120 | — | — | 1.5% | Nov 29, 2018 | The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to a... |
| CVE-2018-15537 | — | — | 5.0% | Nov 29, 2018 | Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain ac... |
| CVE-2018-15981 | — | — | 11.7% | Nov 29, 2018 | Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to ... |
| CVE-2018-15980 | — | — | 7.9% | Nov 29, 2018 | Adobe Photoshop CC versions 19.1.6 and earlier have an out-of-bounds read vulnerability. Successful exploitation could l... |
| CVE-2018-15979 | — | — | 10.3% | Nov 29, 2018 | Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier... |
| CVE-2018-15978 | — | — | 7.4% | Nov 29, 2018 | Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lea... |
| CVE-2018-8789 | — | — | 5.2% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results i... |
| CVE-2018-8788 | — | — | 7.4% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that re... |
| CVE-2018-19693 | — | — | 0.7% | Nov 29, 2018 | An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter. |
| CVE-2018-19692 | — | — | 1.5% | Nov 29, 2018 | An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute a... |
| CVE-2018-11002 | — | — | 0.9% | Nov 29, 2018 | Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions. |
| CVE-2018-18649 | — | — | 6.7% | Nov 29, 2018 | An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, ... |
| CVE-2018-12245 | — | — | 1.1% | Nov 29, 2018 | Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case ... |
| CVE-2018-12239 | — | — | 0.5% | Nov 29, 2018 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection S... |
| CVE-2018-12238 | — | — | 0.4% | Nov 29, 2018 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection S... |
| CVE-2018-19666 | — | — | 0.8% | Nov 29, 2018 | The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversa... |
| CVE-2018-19664 | — | — | 1.7% | Nov 29, 2018 | libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpe... |
| CVE-2018-19662 | — | — | 2.3% | Nov 29, 2018 | An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that wi... |
| CVE-2018-19661 | — | — | 2.1% | Nov 29, 2018 | An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that wi... |
| CVE-2018-19655 | — | — | 2.9% | Nov 29, 2018 | A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other ... |
| CVE-2018-19628 | — | — | 3.1% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl... |
| CVE-2018-19627 | — | — | 17.7% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v... |
| CVE-2018-19626 | — | — | 1.4% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/p... |
| CVE-2018-19625 | — | — | 1.4% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now