2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12411 | HIGH | 7.5 | 0.9% | Nov 6, 2018 | The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpa... |
| CVE-2018-14667 | CRITICAL | 9.8 | 74.2% | Nov 6, 2018 | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou... |
| CVE-2018-17186 | — | — | 2.5% | Nov 6, 2018 | An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not li... |
| CVE-2018-17184 | — | — | 1.2% | Nov 6, 2018 | A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements ... |
| CVE-2018-16475 | — | — | 1.8% | Nov 6, 2018 | A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server. |
| CVE-2018-16474 | — | — | 0.8% | Nov 6, 2018 | A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript. |
| CVE-2018-16473 | — | — | 1.4% | Nov 6, 2018 | A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files. |
| CVE-2018-16472 | HIGH | 7.5 | 2.1% | Nov 6, 2018 | A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.... |
| CVE-2018-9516 | — | — | 0.4% | Nov 6, 2018 | In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds che... |
| CVE-2018-9489 | — | — | 1.0% | Nov 6, 2018 | When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including ... |
| CVE-2018-9488 | — | — | 0.4% | Nov 6, 2018 | In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead... |
| CVE-2018-9465 | — | — | 0.2% | Nov 6, 2018 | In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead ... |
| CVE-2018-9459 | — | — | 1.7% | Nov 6, 2018 | In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privile... |
| CVE-2018-9458 | — | — | 0.6% | Nov 6, 2018 | In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses... |
| CVE-2018-9455 | — | — | 1.6% | Nov 6, 2018 | In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This ... |
| CVE-2018-9454 | — | — | 0.2% | Nov 6, 2018 | In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead ... |
| CVE-2018-9453 | — | — | 0.2% | Nov 6, 2018 | In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds check. This could lea... |
| CVE-2018-9451 | — | — | 0.2% | Nov 6, 2018 | In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. Thi... |
| CVE-2018-9450 | — | — | 2.7% | Nov 6, 2018 | In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This ... |
| CVE-2018-9448 | — | — | 1.7% | Nov 6, 2018 | In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check. This could... |
| CVE-2018-9446 | — | — | 2.1% | Nov 6, 2018 | In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This ... |
| CVE-2018-9445 | — | — | 0.8% | Nov 6, 2018 | In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local ... |
| CVE-2018-9444 | — | — | 0.5% | Nov 6, 2018 | In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead ... |
| CVE-2018-9438 | — | — | 0.2% | Nov 6, 2018 | When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. Thi... |
| CVE-2018-9437 | — | — | 0.9% | Nov 6, 2018 | In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now