2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19067 | — | — | 2.0% | Nov 7, 2018 | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic... |
| CVE-2018-19066 | — | — | 1.6% | Nov 7, 2018 | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic... |
| CVE-2018-19065 | — | — | 1.6% | Nov 7, 2018 | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic... |
| CVE-2018-19064 | — | — | 2.0% | Nov 7, 2018 | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic... |
| CVE-2018-19063 | — | — | 2.0% | Nov 7, 2018 | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic... |
| CVE-2018-19061 | — | — | 1.8% | Nov 7, 2018 | DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter. |
| CVE-2018-19060 | — | — | 1.9% | Nov 7, 2018 | An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial o... |
| CVE-2018-19059 | — | — | 2.1% | Nov 7, 2018 | An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to ... |
| CVE-2018-19058 | MEDIUM | 6.5 | 2.1% | Nov 7, 2018 | An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service becaus... |
| CVE-2018-18590 | CRITICAL | 9.6 | 1.0% | Nov 7, 2018 | A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge conta... |
| CVE-2018-19057 | — | — | 0.8% | Nov 7, 2018 | SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters... |
| CVE-2018-19056 | — | — | 0.8% | Nov 7, 2018 | pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of ... |
| CVE-2018-8021 | — | — | 53.7% | Nov 7, 2018 | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos... |
| CVE-2018-16845 | MEDIUM | 6.1 | 9.8% | Nov 7, 2018 | nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to ca... |
| CVE-2018-16844 | HIGH | 7.5 | 12.4% | Nov 7, 2018 | nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive... |
| CVE-2018-16843 | HIGH | 7.5 | 47.1% | Nov 7, 2018 | nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive... |
| CVE-2018-19053 | — | — | 1.4% | Nov 7, 2018 | PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL gene... |
| CVE-2018-19052 | HIGH | 7.5 | 14.1% | Nov 7, 2018 | An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ p... |
| CVE-2018-19047 | — | — | 2.1% | Nov 7, 2018 | mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<im... |
| CVE-2018-19051 | — | — | 0.7% | Nov 7, 2018 | MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter. |
| CVE-2018-19050 | — | — | 0.7% | Nov 7, 2018 | MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter. |
| CVE-2018-12415 | HIGH | 7.5 | 0.9% | Nov 6, 2018 | The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Ent... |
| CVE-2018-12414 | HIGH | 7.5 | 0.7% | Nov 6, 2018 | The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezv... |
| CVE-2018-12413 | HIGH | 7.5 | 0.9% | Nov 6, 2018 | The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution... |
| CVE-2018-12412 | HIGH | 7.5 | 0.9% | Nov 6, 2018 | The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now