2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20213 | — | — | 1.1% | Dec 18, 2018 | wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via... |
| CVE-2018-19522 | MEDIUM | 5.5 | 0.4% | Dec 18, 2018 | DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffe... |
| CVE-2018-1833 | MEDIUM | 5.3 | 1.7% | Dec 18, 2018 | IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An at... |
| CVE-2018-4015 | HIGH | 8.1 | 0.7% | Dec 18, 2018 | An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration o... |
| CVE-2018-20201 | — | — | 1.1% | Dec 18, 2018 | There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a de... |
| CVE-2018-20199 | MEDIUM | 5.5 | 1.1% | Dec 18, 2018 | A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA... |
| CVE-2018-20198 | — | — | 1.2% | Dec 18, 2018 | A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FA... |
| CVE-2018-20197 | — | — | 1.3% | Dec 18, 2018 | There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in F... |
| CVE-2018-20196 | HIGH | 7.8 | 1.3% | Dec 18, 2018 | There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Fr... |
| CVE-2018-20195 | — | — | 1.2% | Dec 18, 2018 | A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FA... |
| CVE-2018-20194 | — | — | 1.3% | Dec 18, 2018 | There is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in F... |
| CVE-2018-7833 | — | — | 1.4% | Dec 17, 2018 | An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon ... |
| CVE-2018-7812 | — | — | 3.7% | Dec 17, 2018 | An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premiu... |
| CVE-2018-7804 | — | — | 0.9% | Dec 17, 2018 | A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quant... |
| CVE-2018-7797 | — | — | 0.8% | Dec 17, 2018 | A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure ... |
| CVE-2018-11795 | — | — | — | Dec 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-20190 | — | — | 2.6% | Dec 17, 2018 | In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Eval::operator()(Sass::Supports_Operator*) in eval.cp... |
| CVE-2018-20189 | — | — | 2.3% | Dec 17, 2018 | In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of s... |
| CVE-2018-20188 | — | — | 0.5% | Dec 17, 2018 | FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account. |
| CVE-2018-20186 | — | — | 1.2% | Dec 17, 2018 | An issue was discovered in Bento4 1.5.1-627. AP4_Sample::ReadData in Core/Ap4Sample.cpp allows attackers to trigger an a... |
| CVE-2018-20185 | MEDIUM | 5.3 | 2.1% | Dec 17, 2018 | In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPIma... |
| CVE-2018-20184 | — | — | 2.3% | Dec 17, 2018 | In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c... |
| CVE-2018-20133 | — | — | 1.8% | Dec 17, 2018 | ymlref allows code injection. |
| CVE-2018-20123 | MEDIUM | 5.5 | 0.5% | Dec 17, 2018 | pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error. |
| CVE-2018-20092 | — | — | 2.2% | Dec 17, 2018 | PTC ThingWorx Platform through 8.3.0 is vulnerable to a directory traversal attack on ZIP files via a POST request. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now