2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20374An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byt...
CVE-2018-20373Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client.
CVE-2018-20372TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.
CVE-2018-20371PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers...
CVE-2018-20370SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to ...
CVE-2018-20369Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi...
CVE-2018-20368The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the M...
CVE-2018-20331Local attackers can trigger a Kernel Pool Buffer Overflow in Antiy AVL ATool v1.0.0.22. An attacker must first obtain th...
CVE-2018-20367The "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consu...
CVE-2018-20365LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow.
CVE-2018-20364LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
CVE-2018-20363LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
CVE-2018-20362A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA...
CVE-2018-20361An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Adva...
CVE-2018-20360MEDIUM5.5An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freewar...
CVE-2018-20359An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec.c in Free...
CVE-2018-20358An invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict.c in Freeware A...
CVE-2018-20357A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder...
CVE-2018-19863An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in ins...
CVE-2018-20351The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.
CVE-2018-20349The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attac...
CVE-2018-20348libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a de...
CVE-2018-20325There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python....
CVE-2018-20322LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting i...
CVE-2018-20226An organization administrator can add a super administrator in THEHIVE PROJECT Cortex before 2.1.3 due to the lack of ov...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now