2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-6333CRITICAL9.8The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. A...
CVE-2018-6331CRITICAL9.8Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafte...
CVE-2018-6347HIGH7.5An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affe...
CVE-2018-6346HIGH7.5A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular...
CVE-2018-6344HIGH7.5A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulner...
CVE-2018-6343HIGH7.5Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of serv...
CVE-2018-6342CRITICAL9.8react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a comman...
CVE-2018-6341MEDIUM6.1React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names a...
CVE-2018-6340HIGH8.1The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires con...
CVE-2018-6337HIGH7.5folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in m...
CVE-2018-6336HIGH7.8An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks...
CVE-2018-6335HIGH7.5A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to ...
CVE-2018-6334CRITICAL9.8Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not ...
CVE-2018-20623MEDIUM5.5In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archiv...
CVE-2018-20622MEDIUM6.5JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
CVE-2018-6668MEDIUM6.1A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass...
CVE-2018-19937MEDIUM6.6A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by ope...
CVE-2018-18602CRITICAL9.8The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring...
CVE-2018-18601HIGH8.1The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmwa...
CVE-2018-18600HIGH8.1The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parame...
CVE-2018-20618HIGH8.8ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.
CVE-2018-19918MEDIUM5.4CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.
CVE-2018-19906MEDIUM5.4Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter.
CVE-2018-19905MEDIUM5.4HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter.
CVE-2018-19904MEDIUM6.1Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now