2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-19065An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic...
CVE-2018-19064An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic...
CVE-2018-19063An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic...
CVE-2018-19061DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.
CVE-2018-19060An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial o...
CVE-2018-19059An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to ...
CVE-2018-19057SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters...
CVE-2018-19056pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of ...
CVE-2018-8021Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos...
CVE-2018-19053PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL gene...
CVE-2018-19047mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<im...
CVE-2018-19051MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.
CVE-2018-19050MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter.
CVE-2018-17186An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not li...
CVE-2018-17184A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements ...
CVE-2018-16475A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server.
CVE-2018-16474A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.
CVE-2018-16473A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files.
CVE-2018-9516In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds che...
CVE-2018-9489When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including ...
CVE-2018-9488In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead...
CVE-2018-9465In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead ...
CVE-2018-9459In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privile...
CVE-2018-9458In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses...
CVE-2018-9455In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now