2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19787 | MEDIUM | 6.1 | 2.4% | Dec 2, 2018 | An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascrip... |
| CVE-2018-4040 | HIGH | 7.8 | 1.0% | Dec 1, 2018 | An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, ver... |
| CVE-2018-4039 | HIGH | 7.8 | 1.4% | Dec 1, 2018 | An exploitable out-of-bounds write vulnerability exists in the PNG implementation of Atlantis Word Processor, version 3.... |
| CVE-2018-4038 | HIGH | 7.8 | 1.3% | Dec 1, 2018 | An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, v... |
| CVE-2018-3951 | HIGH | 7.2 | 3.9% | Dec 1, 2018 | An exploitable remote code execution vulnerability exists in the HTTP header-parsing function of the TP-Link TL-R600VPN ... |
| CVE-2018-3950 | HIGH | 8.8 | 2.9% | Dec 1, 2018 | An exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VP... |
| CVE-2018-3949 | HIGH | 7.5 | 53.3% | Dec 1, 2018 | An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A... |
| CVE-2018-19785 | — | — | 0.9% | Dec 1, 2018 | PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php. |
| CVE-2018-19784 | — | — | 1.1% | Dec 1, 2018 | The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, whic... |
| CVE-2018-15716 | — | — | 18.5% | Nov 30, 2018 | NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques... |
| CVE-2018-15715 | — | — | 3.5% | Nov 30, 2018 | Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0... |
| CVE-2018-7831 | — | — | 0.6% | Nov 30, 2018 | An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded we... |
| CVE-2018-7830 | — | — | 2.4% | Nov 30, 2018 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedd... |
| CVE-2018-7811 | — | — | 3.5% | Nov 30, 2018 | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLC... |
| CVE-2018-7810 | — | — | 0.9% | Nov 30, 2018 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embe... |
| CVE-2018-7809 | — | — | 2.5% | Nov 30, 2018 | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLC... |
| CVE-2018-7807 | — | — | 1.3% | Nov 30, 2018 | Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the serve... |
| CVE-2018-7806 | — | — | 1.3% | Nov 30, 2018 | Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, ma... |
| CVE-2018-16477 | — | — | 1.3% | Nov 30, 2018 | A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify... |
| CVE-2018-16476 | — | — | 2.6% | Nov 30, 2018 | A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can c... |
| CVE-2018-19290 | — | — | 4.0% | Nov 30, 2018 | In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command... |
| CVE-2018-18987 | — | — | 3.2% | Nov 30, 2018 | VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without... |
| CVE-2018-18983 | — | — | 2.9% | Nov 30, 2018 | VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) in... |
| CVE-2018-18860 | — | — | 1.2% | Nov 30, 2018 | A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-... |
| CVE-2018-15835 | — | — | 2.0% | Nov 30, 2018 | Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now