2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12370 | — | — | 1.1% | Oct 18, 2018 | In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Re... |
| CVE-2018-12369 | — | — | 2.5% | Oct 18, 2018 | WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a mali... |
| CVE-2018-12368 | — | — | 4.8% | Oct 18, 2018 | Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have ... |
| CVE-2018-12367 | — | — | 2.0% | Oct 18, 2018 | In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ab... |
| CVE-2018-12366 | — | — | 3.2% | Oct 18, 2018 | An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a f... |
| CVE-2018-12365 | — | — | 3.2% | Oct 18, 2018 | A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system ... |
| CVE-2018-12364 | — | — | 1.7% | Oct 18, 2018 | NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin PO... |
| CVE-2018-12363 | — | — | 3.1% | Oct 18, 2018 | A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting... |
| CVE-2018-12362 | — | — | 3.8% | Oct 18, 2018 | An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) sc... |
| CVE-2018-12361 | — | — | 2.8% | Oct 18, 2018 | An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for s... |
| CVE-2018-12360 | — | — | 3.1% | Oct 18, 2018 | A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by foc... |
| CVE-2018-12359 | — | — | 4.6% | Oct 18, 2018 | A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dyn... |
| CVE-2018-12358 | — | — | 1.3% | Oct 18, 2018 | Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malici... |
| CVE-2018-18461 | — | — | 4.2% | Oct 18, 2018 | The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers t... |
| CVE-2018-18460 | — | — | 1.0% | Oct 18, 2018 | XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admi... |
| CVE-2018-18459 | — | — | 1.1% | Oct 18, 2018 | The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL po... |
| CVE-2018-18458 | — | — | 1.1% | Oct 18, 2018 | The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL... |
| CVE-2018-18457 | — | — | 1.1% | Oct 18, 2018 | The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL po... |
| CVE-2018-18456 | — | — | 1.0% | Oct 18, 2018 | The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cau... |
| CVE-2018-18455 | — | — | 1.1% | Oct 18, 2018 | The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based ... |
| CVE-2018-18454 | — | — | 1.2% | Oct 18, 2018 | CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buf... |
| CVE-2018-18450 | — | — | 1.5% | Oct 17, 2018 | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demo... |
| CVE-2018-15438 | MEDIUM | 6.5 | 1.2% | Oct 17, 2018 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthentica... |
| CVE-2018-0443 | HIGH | 7.5 | 3.4% | Oct 17, 2018 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless ... |
| CVE-2018-0442 | HIGH | 7.5 | 3.3% | Oct 17, 2018 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now