2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11963 | — | — | 0.2% | Dec 20, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overre... |
| CVE-2018-11961 | — | — | 0.2% | Dec 20, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility o... |
| CVE-2018-11960 | — | — | 0.2% | Dec 20, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after f... |
| CVE-2018-1000852 | MEDIUM | 6.5 | 2.7% | Dec 20, 2018 | FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unkno... |
| CVE-2018-1000851 | — | — | 2.2% | Dec 20, 2018 | Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storag... |
| CVE-2018-1000850 | — | — | 4.0% | Dec 20, 2018 | Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability... |
| CVE-2018-1000849 | — | — | 3.5% | Dec 20, 2018 | Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Al... |
| CVE-2018-1000848 | — | — | 0.6% | Dec 20, 2018 | Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost pag... |
| CVE-2018-1000847 | — | — | 0.8% | Dec 20, 2018 | FreshDNS version 1.0.3 and prior contains a Cross Site Scripting (XSS) vulnerability in Account data form; Zone editor t... |
| CVE-2018-1000846 | — | — | 0.6% | Dec 20, 2018 | FreshDNS version 1.0.3 and earlier contains a Cross ite Request Forgery (CSRF) vulnerability in All (authenticated) API ... |
| CVE-2018-1000845 | — | — | — | Dec 20, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID: CVE-2017-6519. Reason: This candidate is a duplicate of ... |
| CVE-2018-1000844 | — | — | 2.2% | Dec 20, 2018 | Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Ent... |
| CVE-2018-1000843 | — | — | 0.8% | Dec 20, 2018 | Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/lui... |
| CVE-2018-1000842 | MEDIUM | 6.1 | 1.7% | Dec 20, 2018 | FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scr... |
| CVE-2018-1000841 | — | — | 0.7% | Dec 20, 2018 | Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can resu... |
| CVE-2018-1000840 | — | — | 2.2% | Dec 20, 2018 | Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML()... |
| CVE-2018-1000839 | — | — | 3.1% | Dec 20, 2018 | LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Rem... |
| CVE-2018-1000838 | — | — | 2.5% | Dec 20, 2018 | autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result i... |
| CVE-2018-1000837 | CRITICAL | 10 | 1.8% | Dec 20, 2018 | UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can resu... |
| CVE-2018-1000836 | — | — | 1.1% | Dec 20, 2018 | bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleC... |
| CVE-2018-1000835 | CRITICAL | 10 | 1.8% | Dec 20, 2018 | KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can resul... |
| CVE-2018-1000834 | — | — | 1.4% | Dec 20, 2018 | runelite version <= runelite-parent-1.4.23 contains a XML External Entity (XXE) vulnerability in Man in the middle runsc... |
| CVE-2018-1000833 | — | — | 3.2% | Dec 20, 2018 | ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disc... |
| CVE-2018-1000832 | — | — | 6.4% | Dec 20, 2018 | ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disc... |
| CVE-2018-1000831 | — | — | 1.9% | Dec 20, 2018 | K9Mail version <= v5.600 contains a XML External Entity (XXE) vulnerability in WebDAV response parser that can result in... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now