2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19065 | — | — | 1.6% | Nov 7, 2018 | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic... |
| CVE-2018-19064 | — | — | 2.0% | Nov 7, 2018 | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic... |
| CVE-2018-19063 | — | — | 2.0% | Nov 7, 2018 | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic... |
| CVE-2018-19061 | — | — | 1.8% | Nov 7, 2018 | DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter. |
| CVE-2018-19060 | — | — | 1.9% | Nov 7, 2018 | An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial o... |
| CVE-2018-19059 | — | — | 2.1% | Nov 7, 2018 | An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to ... |
| CVE-2018-19057 | — | — | 0.8% | Nov 7, 2018 | SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters... |
| CVE-2018-19056 | — | — | 0.8% | Nov 7, 2018 | pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of ... |
| CVE-2018-8021 | — | — | 53.7% | Nov 7, 2018 | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos... |
| CVE-2018-19053 | — | — | 1.4% | Nov 7, 2018 | PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL gene... |
| CVE-2018-19047 | — | — | 2.1% | Nov 7, 2018 | mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<im... |
| CVE-2018-19051 | — | — | 0.7% | Nov 7, 2018 | MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter. |
| CVE-2018-19050 | — | — | 0.7% | Nov 7, 2018 | MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter. |
| CVE-2018-17186 | — | — | 2.5% | Nov 6, 2018 | An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not li... |
| CVE-2018-17184 | — | — | 1.2% | Nov 6, 2018 | A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements ... |
| CVE-2018-16475 | — | — | 1.8% | Nov 6, 2018 | A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server. |
| CVE-2018-16474 | — | — | 0.8% | Nov 6, 2018 | A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript. |
| CVE-2018-16473 | — | — | 1.4% | Nov 6, 2018 | A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files. |
| CVE-2018-9516 | — | — | 0.4% | Nov 6, 2018 | In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds che... |
| CVE-2018-9489 | — | — | 1.0% | Nov 6, 2018 | When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including ... |
| CVE-2018-9488 | — | — | 0.4% | Nov 6, 2018 | In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead... |
| CVE-2018-9465 | — | — | 0.2% | Nov 6, 2018 | In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead ... |
| CVE-2018-9459 | — | — | 1.7% | Nov 6, 2018 | In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privile... |
| CVE-2018-9458 | — | — | 0.6% | Nov 6, 2018 | In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses... |
| CVE-2018-9455 | — | — | 1.6% | Nov 6, 2018 | In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now