2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000830 | — | — | 1.5% | Dec 20, 2018 | XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Dis... |
| CVE-2018-1000829 | — | — | 1.3% | Dec 20, 2018 | Anyplace version before commit 80359b4 contains a XML External Entity (XXE) vulnerability in Man in the middle on map AP... |
| CVE-2018-1000828 | CRITICAL | 9 | 1.3% | Dec 20, 2018 | FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the ... |
| CVE-2018-1000827 | — | — | 3.6% | Dec 20, 2018 | Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclos... |
| CVE-2018-1000826 | — | — | 1.3% | Dec 20, 2018 | Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can re... |
| CVE-2018-1000825 | — | — | 1.9% | Dec 20, 2018 | FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that... |
| CVE-2018-1000824 | — | — | 3.2% | Dec 20, 2018 | MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosu... |
| CVE-2018-1000823 | CRITICAL | 10 | 1.9% | Dec 20, 2018 | exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can res... |
| CVE-2018-1000822 | — | — | 1.9% | Dec 20, 2018 | codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser th... |
| CVE-2018-1000821 | — | — | 1.9% | Dec 20, 2018 | MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files t... |
| CVE-2018-1000820 | — | — | 1.9% | Dec 20, 2018 | neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in ... |
| CVE-2018-1000817 | — | — | 2.5% | Dec 20, 2018 | Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Acce... |
| CVE-2018-1000816 | — | — | 0.7% | Dec 20, 2018 | Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphi... |
| CVE-2018-1000815 | — | — | 1.1% | Dec 20, 2018 | Brave Software Inc. Brave version version 0.22.810 to 0.24.0 contains a Other/Unknown vulnerability in function ContentS... |
| CVE-2018-1000814 | MEDIUM | 6.5 | 1.0% | Dec 20, 2018 | aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and ... |
| CVE-2018-1000813 | — | — | 0.7% | Dec 20, 2018 | Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom cl... |
| CVE-2018-1000812 | — | — | 2.0% | Dec 20, 2018 | Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mech... |
| CVE-2018-1000811 | — | — | 47.6% | Dec 20, 2018 | bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages... |
| CVE-2018-7365 | MEDIUM | 5.1 | 0.7% | Dec 20, 2018 | All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerabili... |
| CVE-2018-5200 | HIGH | 7.8 | 1.7% | Dec 20, 2018 | KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV ... |
| CVE-2018-5199 | HIGH | 8.8 | 1.7% | Dec 20, 2018 | In Veraport G3 ALL on MacOS, due to insufficient domain validation, It is possible to overwrite installation file to mal... |
| CVE-2018-5198 | HIGH | 8.1 | 1.4% | Dec 20, 2018 | In Veraport G3 ALL on MacOS, a race condition when calling the Veraport API allow remote attacker to cause arbitrary fil... |
| CVE-2018-1973 | HIGH | 7.2 | 2.3% | Dec 20, 2018 | IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves fu... |
| CVE-2018-1784 | HIGH | 7.1 | 1.7% | Dec 20, 2018 | IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IB... |
| CVE-2018-1778 | HIGH | 7.7 | 3.4% | Dec 20, 2018 | IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication i... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now