2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19541 | — | — | 2.8% | Nov 26, 2018 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16... |
| CVE-2018-19540 | — | — | 2.3% | Nov 26, 2018 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16... |
| CVE-2018-19539 | — | — | 1.9% | Nov 26, 2018 | An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/b... |
| CVE-2018-19537 | — | — | 6.0% | Nov 26, 2018 | TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_ho... |
| CVE-2018-19535 | MEDIUM | 6.5 | 2.1% | Nov 26, 2018 | In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (applica... |
| CVE-2018-19532 | — | — | 1.7% | Nov 26, 2018 | A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoF... |
| CVE-2018-19531 | — | — | 4.6% | Nov 26, 2018 | HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function us... |
| CVE-2018-19530 | — | — | 4.6% | Nov 26, 2018 | HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function us... |
| CVE-2018-19528 | — | — | 2.7% | Nov 26, 2018 | TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted... |
| CVE-2018-19520 | — | — | 2.9% | Nov 25, 2018 | An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in... |
| CVE-2018-19519 | — | — | 2.4% | Nov 25, 2018 | In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet ... |
| CVE-2018-19518 | HIGH | 7.5 | 95.2% | Nov 25, 2018 | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c... |
| CVE-2018-19517 | — | — | 0.8% | Nov 24, 2018 | An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a m... |
| CVE-2018-19504 | — | — | 1.4% | Nov 23, 2018 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilt... |
| CVE-2018-19503 | — | — | 1.5% | Nov 23, 2018 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a stack-based buffer overflow in t... |
| CVE-2018-19502 | — | — | 1.5% | Nov 23, 2018 | An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in th... |
| CVE-2018-19499 | — | — | 2.0% | Nov 23, 2018 | Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a rea... |
| CVE-2018-19492 | — | — | 1.6% | Nov 23, 2018 | An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with a... |
| CVE-2018-19491 | — | — | 1.6% | Nov 23, 2018 | An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an... |
| CVE-2018-19490 | — | — | 1.6% | Nov 23, 2018 | An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer ove... |
| CVE-2018-19486 | — | — | 4.1% | Nov 23, 2018 | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $... |
| CVE-2018-19477 | — | — | 3.0% | Nov 23, 2018 | psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because ... |
| CVE-2018-19476 | — | — | 3.0% | Nov 23, 2018 | psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of ... |
| CVE-2018-19475 | — | — | 9.5% | Nov 23, 2018 | psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because... |
| CVE-2018-19469 | — | — | 0.6% | Nov 23, 2018 | ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now