2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12370In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Re...
CVE-2018-12369WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a mali...
CVE-2018-12368Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have ...
CVE-2018-12367In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ab...
CVE-2018-12366An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a f...
CVE-2018-12365A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system ...
CVE-2018-12364NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin PO...
CVE-2018-12363A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting...
CVE-2018-12362An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) sc...
CVE-2018-12361An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for s...
CVE-2018-12360A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by foc...
CVE-2018-12359A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dyn...
CVE-2018-12358Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malici...
CVE-2018-18461The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers t...
CVE-2018-18460XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admi...
CVE-2018-18459The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL po...
CVE-2018-18458The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL...
CVE-2018-18457The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL po...
CVE-2018-18456The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cau...
CVE-2018-18455The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based ...
CVE-2018-18454CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buf...
CVE-2018-18450apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demo...
CVE-2018-15438MEDIUM6.5A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthentica...
CVE-2018-0443HIGH7.5A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless ...
CVE-2018-0442HIGH7.5A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now