2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12364 | — | — | 1.7% | Oct 18, 2018 | NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin PO... |
| CVE-2018-12363 | — | — | 3.1% | Oct 18, 2018 | A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting... |
| CVE-2018-12362 | — | — | 3.8% | Oct 18, 2018 | An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) sc... |
| CVE-2018-12361 | — | — | 2.8% | Oct 18, 2018 | An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for s... |
| CVE-2018-12360 | — | — | 3.1% | Oct 18, 2018 | A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by foc... |
| CVE-2018-12359 | — | — | 4.6% | Oct 18, 2018 | A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dyn... |
| CVE-2018-12358 | — | — | 1.3% | Oct 18, 2018 | Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malici... |
| CVE-2018-18461 | — | — | 4.2% | Oct 18, 2018 | The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers t... |
| CVE-2018-18460 | — | — | 1.0% | Oct 18, 2018 | XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admi... |
| CVE-2018-18459 | — | — | 1.1% | Oct 18, 2018 | The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL po... |
| CVE-2018-18458 | — | — | 1.1% | Oct 18, 2018 | The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL... |
| CVE-2018-18457 | — | — | 1.1% | Oct 18, 2018 | The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL po... |
| CVE-2018-18456 | — | — | 1.0% | Oct 18, 2018 | The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cau... |
| CVE-2018-18455 | — | — | 1.1% | Oct 18, 2018 | The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based ... |
| CVE-2018-18454 | — | — | 1.2% | Oct 18, 2018 | CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buf... |
| CVE-2018-18450 | — | — | 1.5% | Oct 17, 2018 | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demo... |
| CVE-2018-14597 | — | — | 1.3% | Oct 17, 2018 | CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 1... |
| CVE-2018-18386 | — | — | 0.4% | Oct 17, 2018 | drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) ... |
| CVE-2018-18444 | — | — | 2.6% | Oct 17, 2018 | makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possib... |
| CVE-2018-18443 | — | — | 2.1% | Oct 17, 2018 | OpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool.cpp, as demonstrated by exrmultiview. |
| CVE-2018-15976 | — | — | 5.4% | Oct 17, 2018 | Adobe Technical Communications Suite versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnera... |
| CVE-2018-15974 | — | — | 4.6% | Oct 17, 2018 | Adobe Framemaker versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnerability. Successful e... |
| CVE-2018-15973 | — | — | 2.4% | Oct 17, 2018 | Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successf... |
| CVE-2018-15972 | — | — | 2.4% | Oct 17, 2018 | Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successf... |
| CVE-2018-15971 | — | — | 1.9% | Oct 17, 2018 | Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Succe... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now