2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16640 | — | — | 2.5% | Sep 6, 2018 | ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c. |
| CVE-2018-5389 | — | — | 3.0% | Sep 6, 2018 | The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair ac... |
| CVE-2018-5005 | — | — | 3.9% | Sep 6, 2018 | Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerability. Successful expl... |
| CVE-2018-16622 | — | — | 0.8% | Sep 6, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to i... |
| CVE-2018-1000670 | — | — | 0.6% | Sep 6, 2018 | KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting ... |
| CVE-2018-1000669 | — | — | 0.5% | Sep 6, 2018 | KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Fo... |
| CVE-2018-1000801 | — | — | 1.8% | Sep 6, 2018 | okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" i... |
| CVE-2018-1000671 | — | — | 4.0% | Sep 6, 2018 | sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ... |
| CVE-2018-1000800 | — | — | 1.7% | Sep 6, 2018 | zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get(... |
| CVE-2018-1000668 | — | — | 0.9% | Sep 6, 2018 | jsish version 2.4.70 2.047 contains a CWE-125: Out-of-bounds Read vulnerability in function jsi_ObjArrayLookup (jsiObj.c... |
| CVE-2018-1000667 | — | — | 1.2% | Sep 6, 2018 | NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handli... |
| CVE-2018-1000666 | — | — | 8.1% | Sep 6, 2018 | GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: I... |
| CVE-2018-1000665 | — | — | 1.3% | Sep 6, 2018 | Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in u... |
| CVE-2018-1000664 | — | — | 0.5% | Sep 6, 2018 | daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnera... |
| CVE-2018-1000663 | — | — | 0.9% | Sep 6, 2018 | jsish version 2.4.70 2.047 contains a Buffer Overflow vulnerability in function _jsi_evalcode from jsiEval.c that can re... |
| CVE-2018-1000661 | — | — | 0.9% | Sep 6, 2018 | jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can ... |
| CVE-2018-1000660 | — | — | 1.3% | Sep 6, 2018 | TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b... |
| CVE-2018-1000659 | — | — | 3.6% | Sep 6, 2018 | LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulne... |
| CVE-2018-1000658 | — | — | 2.1% | Sep 6, 2018 | LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an at... |
| CVE-2018-16606 | — | — | 5.9% | Sep 6, 2018 | In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted paper... |
| CVE-2018-16604 | — | — | 1.5% | Sep 6, 2018 | An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary P... |
| CVE-2018-1000773 | — | — | 7.3% | Sep 6, 2018 | WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can re... |
| CVE-2018-16585 | — | — | 1.7% | Sep 6, 2018 | An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even th... |
| CVE-2018-11263 | — | — | 0.5% | Sep 6, 2018 | In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is ... |
| CVE-2018-16459 | — | — | 0.8% | Sep 6, 2018 | An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now