2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20213wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via...
CVE-2018-19522MEDIUM5.5DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffe...
CVE-2018-1833MEDIUM5.3IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An at...
CVE-2018-4015HIGH8.1An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration o...
CVE-2018-20201There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a de...
CVE-2018-20199MEDIUM5.5A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA...
CVE-2018-20198A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA...
CVE-2018-20197There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in F...
CVE-2018-20196HIGH7.8There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Fr...
CVE-2018-20195A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FA...
CVE-2018-20194There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in F...
CVE-2018-7833An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon ...
CVE-2018-7812An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premiu...
CVE-2018-7804A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quant...
CVE-2018-7797A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure ...
CVE-2018-11795Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-20190In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Eval::operator()(Sass::Supports_Operator*) in eval.cp...
CVE-2018-20189In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of s...
CVE-2018-20188FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
CVE-2018-20186An issue was discovered in Bento4 1.5.1-627. AP4_Sample::ReadData in Core/Ap4Sample.cpp allows attackers to trigger an a...
CVE-2018-20185MEDIUM5.3In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPIma...
CVE-2018-20184In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c...
CVE-2018-20133ymlref allows code injection.
CVE-2018-20123MEDIUM5.5pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
CVE-2018-20092PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now