2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19787MEDIUM6.1An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascrip...
CVE-2018-4040HIGH7.8An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, ver...
CVE-2018-4039HIGH7.8An exploitable out-of-bounds write vulnerability exists in the PNG implementation of Atlantis Word Processor, version 3....
CVE-2018-4038HIGH7.8An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, v...
CVE-2018-3951HIGH7.2An exploitable remote code execution vulnerability exists in the HTTP header-parsing function of the TP-Link TL-R600VPN ...
CVE-2018-3950HIGH8.8An exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VP...
CVE-2018-3949HIGH7.5An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A...
CVE-2018-19785PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php.
CVE-2018-19784The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, whic...
CVE-2018-15716NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques...
CVE-2018-15715Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0...
CVE-2018-7831An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded we...
CVE-2018-7830Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedd...
CVE-2018-7811An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLC...
CVE-2018-7810An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embe...
CVE-2018-7809An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLC...
CVE-2018-7807Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the serve...
CVE-2018-7806Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, ma...
CVE-2018-16477A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify...
CVE-2018-16476A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can c...
CVE-2018-19290In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command...
CVE-2018-18987VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without...
CVE-2018-18983VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) in...
CVE-2018-18860A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-...
CVE-2018-15835Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now