2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000818 | — | — | — | Nov 29, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-19132. Reason: This candidate is a reservation... |
| CVE-2018-19752 | — | — | 3.3% | Nov 29, 2018 | DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar. |
| CVE-2018-19751 | — | — | 3.3% | Nov 29, 2018 | DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields. |
| CVE-2018-19750 | — | — | 1.8% | Nov 29, 2018 | DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma... |
| CVE-2018-19749 | — | — | 3.3% | Nov 29, 2018 | DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field. |
| CVE-2018-18619 | — | — | 4.2% | Nov 29, 2018 | internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability bec... |
| CVE-2018-19748 | — | — | 2.0% | Nov 29, 2018 | app/plug/attachment/controller/admincontroller.php in SDCMS 1.6 allows reading arbitrary files via a /?m=plug&c=admin&a=... |
| CVE-2018-19120 | — | — | 1.5% | Nov 29, 2018 | The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to a... |
| CVE-2018-15537 | — | — | 5.0% | Nov 29, 2018 | Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain ac... |
| CVE-2018-15981 | — | — | 11.7% | Nov 29, 2018 | Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to ... |
| CVE-2018-15980 | — | — | 7.9% | Nov 29, 2018 | Adobe Photoshop CC versions 19.1.6 and earlier have an out-of-bounds read vulnerability. Successful exploitation could l... |
| CVE-2018-15979 | — | — | 10.3% | Nov 29, 2018 | Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier... |
| CVE-2018-15978 | — | — | 7.4% | Nov 29, 2018 | Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lea... |
| CVE-2018-8789 | — | — | 5.2% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results i... |
| CVE-2018-8788 | — | — | 7.4% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that re... |
| CVE-2018-8787 | CRITICAL | 9.8 | 8.4% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function g... |
| CVE-2018-8786 | CRITICAL | 9.8 | 8.2% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function... |
| CVE-2018-8785 | CRITICAL | 9.8 | 7.3% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a... |
| CVE-2018-8784 | CRITICAL | 9.8 | 7.3% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that resu... |
| CVE-2018-19693 | — | — | 0.7% | Nov 29, 2018 | An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter. |
| CVE-2018-19692 | — | — | 1.5% | Nov 29, 2018 | An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute a... |
| CVE-2018-16859 | MEDIUM | 4.2 | 0.5% | Nov 29, 2018 | Execution of Ansible playbooks on Windows platforms with PowerShell ScriptBlock logging and Module logging enabled can a... |
| CVE-2018-14626 | MEDIUM | 5.3 | 2.7% | Nov 29, 2018 | PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerab... |
| CVE-2018-10851 | MEDIUM | 5.3 | 6.0% | Nov 29, 2018 | PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excludi... |
| CVE-2018-1762 | MEDIUM | 5.4 | 1.0% | Nov 29, 2018 | IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scr... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now