2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6333 | CRITICAL | 9.8 | 2.3% | Dec 31, 2018 | The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. A... |
| CVE-2018-6331 | CRITICAL | 9.8 | 2.5% | Dec 31, 2018 | Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafte... |
| CVE-2018-6347 | HIGH | 7.5 | 1.4% | Dec 31, 2018 | An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affe... |
| CVE-2018-6346 | HIGH | 7.5 | 1.4% | Dec 31, 2018 | A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular... |
| CVE-2018-6344 | HIGH | 7.5 | 1.9% | Dec 31, 2018 | A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulner... |
| CVE-2018-6343 | HIGH | 7.5 | 0.8% | Dec 31, 2018 | Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of serv... |
| CVE-2018-6342 | CRITICAL | 9.8 | 2.8% | Dec 31, 2018 | react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a comman... |
| CVE-2018-6341 | MEDIUM | 6.1 | 3.4% | Dec 31, 2018 | React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names a... |
| CVE-2018-6340 | HIGH | 8.1 | 1.4% | Dec 31, 2018 | The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires con... |
| CVE-2018-6337 | HIGH | 7.5 | 1.8% | Dec 31, 2018 | folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in m... |
| CVE-2018-6336 | HIGH | 7.8 | 0.5% | Dec 31, 2018 | An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks... |
| CVE-2018-6335 | HIGH | 7.5 | 1.5% | Dec 31, 2018 | A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to ... |
| CVE-2018-6334 | CRITICAL | 9.8 | 1.9% | Dec 31, 2018 | Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not ... |
| CVE-2018-20623 | MEDIUM | 5.5 | 1.8% | Dec 31, 2018 | In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archiv... |
| CVE-2018-20622 | MEDIUM | 6.5 | 2.9% | Dec 31, 2018 | JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. |
| CVE-2018-6668 | MEDIUM | 6.1 | 0.4% | Dec 31, 2018 | A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass... |
| CVE-2018-19937 | MEDIUM | 6.6 | 0.3% | Dec 31, 2018 | A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by ope... |
| CVE-2018-18602 | CRITICAL | 9.8 | 1.4% | Dec 31, 2018 | The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring... |
| CVE-2018-18601 | HIGH | 8.1 | 1.2% | Dec 31, 2018 | The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmwa... |
| CVE-2018-18600 | HIGH | 8.1 | 1.6% | Dec 31, 2018 | The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parame... |
| CVE-2018-20618 | HIGH | 8.8 | 1.4% | Dec 31, 2018 | ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c. |
| CVE-2018-19918 | MEDIUM | 5.4 | 0.7% | Dec 31, 2018 | CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI. |
| CVE-2018-19906 | MEDIUM | 5.4 | 0.7% | Dec 31, 2018 | Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter. |
| CVE-2018-19905 | MEDIUM | 5.4 | 0.7% | Dec 31, 2018 | HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. |
| CVE-2018-19904 | MEDIUM | 6.1 | 0.9% | Dec 31, 2018 | Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now