2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20467 | MEDIUM | 6.5 | 3.1% | Dec 26, 2018 | In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and... |
| CVE-2018-20465 | — | — | 1.1% | Dec 25, 2018 | Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side templa... |
| CVE-2018-20464 | — | — | 0.7% | Dec 25, 2018 | There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered... |
| CVE-2018-20463 | — | — | 13.4% | Dec 25, 2018 | An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../... |
| CVE-2018-20462 | — | — | 4.0% | Dec 25, 2018 | An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows rem... |
| CVE-2018-20461 | — | — | 1.0% | Dec 25, 2018 | In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (applic... |
| CVE-2018-20460 | — | — | 1.1% | Dec 25, 2018 | In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial... |
| CVE-2018-20459 | MEDIUM | 5.5 | 0.9% | Dec 25, 2018 | In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-... |
| CVE-2018-20458 | MEDIUM | 5.5 | 0.9% | Dec 25, 2018 | In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a d... |
| CVE-2018-20457 | MEDIUM | 5.5 | 0.9% | Dec 25, 2018 | In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-ser... |
| CVE-2018-20456 | — | — | 1.0% | Dec 25, 2018 | In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denia... |
| CVE-2018-20455 | — | — | 1.0% | Dec 25, 2018 | In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denia... |
| CVE-2018-20454 | — | — | 0.7% | Dec 25, 2018 | An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter. |
| CVE-2018-20453 | — | — | 0.9% | Dec 25, 2018 | The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers ... |
| CVE-2018-20452 | — | — | 1.5% | Dec 25, 2018 | The read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of serv... |
| CVE-2018-20451 | MEDIUM | 6.5 | 0.9% | Dec 25, 2018 | The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attacke... |
| CVE-2018-20450 | — | — | 1.1% | Dec 25, 2018 | The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (ap... |
| CVE-2018-20448 | — | — | 1.7% | Dec 25, 2018 | Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. |
| CVE-2018-20445 | CRITICAL | 9.8 | 1.9% | Dec 25, 2018 | D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover Wi... |
| CVE-2018-20444 | — | — | 1.3% | Dec 25, 2018 | Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU devices allow remote attackers to discover Wi-Fi cred... |
| CVE-2018-20443 | — | — | 1.4% | Dec 25, 2018 | Technicolor TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT devices allow remote attackers to discover Wi-Fi credentia... |
| CVE-2018-20442 | — | — | 1.4% | Dec 25, 2018 | Technicolor TC7110.B STC8.62.02 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.... |
| CVE-2018-20441 | — | — | 1.4% | Dec 25, 2018 | Technicolor TC7200.TH2v2 SC05.00.22 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.... |
| CVE-2018-20440 | — | — | 1.4% | Dec 25, 2018 | Technicolor CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC devices allow remote attackers to discover Wi-Fi credentials via... |
| CVE-2018-20439 | — | — | 1.3% | Dec 25, 2018 | Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a devices allow remote attackers to discover Wi-Fi credenti... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now