2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18197 | — | — | 1.4% | Oct 9, 2018 | An issue was discovered in libgig 4.1.0. There is an operator new[] failure (due to a big pSampleLoops heap request) in ... |
| CVE-2018-18196 | — | — | 1.2% | Oct 9, 2018 | An issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in RIFF::List::GetListTypeString in RIFF... |
| CVE-2018-18195 | — | — | 0.9% | Oct 9, 2018 | An issue was discovered in libgig 4.1.0. There is an FPE (divide-by-zero error) in DLS::Sample::Sample in DLS.cpp. |
| CVE-2018-18194 | — | — | 1.2% | Oct 9, 2018 | An issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in DLS::Region::GetSample() in DLS.cpp. |
| CVE-2018-18193 | — | — | 1.2% | Oct 9, 2018 | An issue was discovered in libgig 4.1.0. There is operator new[] failure (due to a big pWavePoolTable heap request) in D... |
| CVE-2018-18192 | — | — | 0.9% | Oct 9, 2018 | An issue was discovered in libgig 4.1.0. There is a NULL pointer dereference in the function DLS::File::GetFirstSample()... |
| CVE-2018-18191 | — | — | 0.8% | Oct 9, 2018 | Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote ... |
| CVE-2018-18190 | — | — | 0.9% | Oct 9, 2018 | An issue was discovered in GoPro gpmf-parser before 1.2.1. There is a divide-by-zero error in GPMF_ScaledData in GPMF_pa... |
| CVE-2018-18088 | — | — | 2.1% | Oct 9, 2018 | OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c |
| CVE-2018-18087 | — | — | 0.7% | Oct 9, 2018 | The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inje... |
| CVE-2018-18086 | — | — | 1.5% | Oct 9, 2018 | EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable... |
| CVE-2018-18083 | — | — | 2.5% | Oct 9, 2018 | An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter b... |
| CVE-2018-18082 | — | — | 0.7% | Oct 9, 2018 | XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=... |
| CVE-2018-18075 | — | — | 1.8% | Oct 9, 2018 | WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=searc... |
| CVE-2018-18029 | — | — | 0.6% | Oct 9, 2018 | Navigate CMS has Stored XSS via the navigate.php Title field in an edit action. |
| CVE-2018-15543 | — | — | 0.4% | Oct 9, 2018 | An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for B... |
| CVE-2018-15542 | — | — | 0.3% | Oct 9, 2018 | An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authen... |
| CVE-2018-14081 | — | — | 1.5% | Oct 9, 2018 | An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device ... |
| CVE-2018-14080 | — | — | 1.8% | Oct 9, 2018 | An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can... |
| CVE-2018-7928 | — | — | 0.3% | Oct 9, 2018 | There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the ... |
| CVE-2018-2475 | — | — | 1.3% | Oct 9, 2018 | Following the Gardener architecture, the Kubernetes apiserver of a Gardener managed shoot cluster resides in the corresp... |
| CVE-2018-2474 | — | — | 0.7% | Oct 9, 2018 | SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticate... |
| CVE-2018-2472 | — | — | 1.0% | Oct 9, 2018 | SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently e... |
| CVE-2018-2471 | — | — | 1.7% | Oct 9, 2018 | Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access i... |
| CVE-2018-2470 | — | — | 1.0% | Oct 9, 2018 | In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now