2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18346 | — | — | 1.3% | Dec 11, 2018 | Incorrect handling of alert box display in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to pre... |
| CVE-2018-18345 | — | — | 1.4% | Dec 11, 2018 | Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who h... |
| CVE-2018-18344 | — | — | 1.5% | Dec 11, 2018 | Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.... |
| CVE-2018-18343 | — | — | 1.4% | Dec 11, 2018 | Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote a... |
| CVE-2018-18342 | — | — | 2.7% | Dec 11, 2018 | Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds... |
| CVE-2018-18341 | — | — | 1.5% | Dec 11, 2018 | An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote a... |
| CVE-2018-18340 | — | — | 1.4% | Dec 11, 2018 | Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentia... |
| CVE-2018-18339 | — | — | 1.4% | Dec 11, 2018 | Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially e... |
| CVE-2018-18338 | — | — | 1.4% | Dec 11, 2018 | Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to po... |
| CVE-2018-18337 | — | — | 1.7% | Dec 11, 2018 | Incorrect handling of stylesheets leading to a use after free in Blink in Google Chrome prior to 71.0.3578.80 allowed a ... |
| CVE-2018-18336 | — | — | 1.5% | Dec 11, 2018 | Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exp... |
| CVE-2018-18335 | — | — | 3.7% | Dec 11, 2018 | Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit hea... |
| CVE-2018-17481 | — | — | 1.6% | Dec 11, 2018 | Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potent... |
| CVE-2018-17480 | HIGH | 8.8 | 34.3% | Dec 11, 2018 | Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chr... |
| CVE-2018-1654 | MEDIUM | 6.8 | 1.3% | Dec 11, 2018 | IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phish... |
| CVE-2018-1652 | MEDIUM | 6.2 | 0.4% | Dec 11, 2018 | IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.... |
| CVE-2018-20059 | — | — | 1.5% | Dec 11, 2018 | jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE. |
| CVE-2018-20058 | — | — | 1.4% | Dec 11, 2018 | In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-2863... |
| CVE-2018-20057 | — | — | 7.4% | Dec 11, 2018 | An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd... |
| CVE-2018-20056 | — | — | 7.0% | Dec 11, 2018 | An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-... |
| CVE-2018-20051 | — | — | 1.4% | Dec 10, 2018 | Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of... |
| CVE-2018-20050 | — | — | 1.5% | Dec 10, 2018 | Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause... |
| CVE-2018-15757 | — | — | — | Dec 10, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-20029 | MEDIUM | 5.5 | 0.3% | Dec 10, 2018 | The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a d... |
| CVE-2018-16636 | — | — | 1.0% | Dec 10, 2018 | Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now