2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12411HIGH7.5The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpa...
CVE-2018-14667CRITICAL9.8The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou...
CVE-2018-17186An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not li...
CVE-2018-17184A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements ...
CVE-2018-16475A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server.
CVE-2018-16474A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.
CVE-2018-16473A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files.
CVE-2018-16472HIGH7.5A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object....
CVE-2018-9516In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds che...
CVE-2018-9489When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including ...
CVE-2018-9488In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead...
CVE-2018-9465In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead ...
CVE-2018-9459In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privile...
CVE-2018-9458In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses...
CVE-2018-9455In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This ...
CVE-2018-9454In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead ...
CVE-2018-9453In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds check. This could lea...
CVE-2018-9451In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. Thi...
CVE-2018-9450In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This ...
CVE-2018-9448In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check. This could...
CVE-2018-9446In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This ...
CVE-2018-9445In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local ...
CVE-2018-9444In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead ...
CVE-2018-9438When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. Thi...
CVE-2018-9437In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now