2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20482 | MEDIUM | 4.7 | 0.5% | Dec 26, 2018 | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to c... |
| CVE-2018-20467 | MEDIUM | 6.5 | 3.1% | Dec 26, 2018 | In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and... |
| CVE-2018-20459 | MEDIUM | 5.5 | 0.9% | Dec 25, 2018 | In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-... |
| CVE-2018-20458 | MEDIUM | 5.5 | 0.9% | Dec 25, 2018 | In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a d... |
| CVE-2018-20457 | MEDIUM | 5.5 | 0.9% | Dec 25, 2018 | In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-ser... |
| CVE-2018-20451 | MEDIUM | 6.5 | 0.9% | Dec 25, 2018 | The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attacke... |
| CVE-2018-8917 | MEDIUM | 6.5 | 0.8% | Dec 24, 2018 | Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows rem... |
| CVE-2018-8918 | MEDIUM | 6.5 | 0.8% | Dec 24, 2018 | Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote at... |
| CVE-2018-20360 | MEDIUM | 5.5 | 1.1% | Dec 22, 2018 | An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freewar... |
| CVE-2018-20124 | MEDIUM | 5.5 | 0.5% | Dec 20, 2018 | hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with... |
| CVE-2018-20126 | MEDIUM | 5.5 | 0.5% | Dec 20, 2018 | hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled. |
| CVE-2018-1000880 | MEDIUM | 6.5 | 4.1% | Dec 20, 2018 | libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: I... |
| CVE-2018-1000879 | MEDIUM | 6.5 | 3.4% | Dec 20, 2018 | libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: ... |
| CVE-2018-1000874 | MEDIUM | 6.1 | 0.8% | Dec 20, 2018 | PHP cebe markdown parser version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in all distribute... |
| CVE-2018-1000873 | MEDIUM | 6.5 | 4.8% | Dec 20, 2018 | Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Jav... |
| CVE-2018-1000855 | MEDIUM | 6.1 | 0.9% | Dec 20, 2018 | easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is moun... |
| CVE-2018-1000852 | MEDIUM | 6.5 | 2.7% | Dec 20, 2018 | FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unkno... |
| CVE-2018-1000842 | MEDIUM | 6.1 | 1.7% | Dec 20, 2018 | FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scr... |
| CVE-2018-1000814 | MEDIUM | 6.5 | 1.0% | Dec 20, 2018 | aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and ... |
| CVE-2018-7365 | MEDIUM | 5.1 | 0.7% | Dec 20, 2018 | All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerabili... |
| CVE-2018-1677 | MEDIUM | 5.1 | 0.4% | Dec 20, 2018 | IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of serv... |
| CVE-2018-1661 | MEDIUM | 6.5 | 0.9% | Dec 20, 2018 | IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attac... |
| CVE-2018-6669 | MEDIUM | 6.3 | 0.5% | Dec 20, 2018 | A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or loca... |
| CVE-2018-20307 | MEDIUM | 4.3 | 0.8% | Dec 20, 2018 | Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain ... |
| CVE-2018-19522 | MEDIUM | 5.5 | 0.4% | Dec 18, 2018 | DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x800020F4) with a buffe... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now