2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14449 | — | — | 1.2% | Jul 20, 2018 | An issue was discovered in libgig 4.1.0. There is an out of bounds read in gig::File::UpdateChunks in gig.cpp. |
| CVE-2018-14448 | — | — | 1.2% | Jul 20, 2018 | Codec::parse in track.cpp in Untrunc through 2018-06-07 has a NULL pointer dereference via a crafted MP4 file because of... |
| CVE-2018-14447 | — | — | 1.8% | Jul 20, 2018 | trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read. |
| CVE-2018-14446 | — | — | 2.4% | Jul 20, 2018 | MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-ba... |
| CVE-2018-14445 | — | — | 1.4% | Jul 20, 2018 | In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinit... |
| CVE-2018-14444 | — | — | 1.1% | Jul 20, 2018 | libdxfrw 0.6.3 has an Integer Overflow in dwgCompressor::decompress18 in dwgutil.cpp, leading to an out-of-bounds read a... |
| CVE-2018-14443 | — | — | 1.1% | Jul 20, 2018 | get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV). |
| CVE-2018-14442 | — | — | 4.7% | Jul 20, 2018 | Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4s... |
| CVE-2018-8018 | — | — | 6.8% | Jul 20, 2018 | In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowe... |
| CVE-2018-14422 | — | — | 0.7% | Jul 20, 2018 | blog/index.php in SansCMS 0.7 has XSS via the q parameter. |
| CVE-2018-14421 | — | — | 0.9% | Jul 20, 2018 | SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin... |
| CVE-2018-14420 | — | — | 0.5% | Jul 20, 2018 | MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by a... |
| CVE-2018-14419 | — | — | 0.5% | Jul 20, 2018 | MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page. |
| CVE-2018-14418 | — | — | 9.1% | Jul 20, 2018 | In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI. |
| CVE-2018-14415 | — | — | 0.8% | Jul 20, 2018 | An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admi... |
| CVE-2018-14441 | — | — | 1.2% | Jul 20, 2018 | An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.act... |
| CVE-2018-14440 | — | — | 1.1% | Jul 20, 2018 | An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeMa... |
| CVE-2018-14439 | — | — | 1.0% | Jul 20, 2018 | espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four d... |
| CVE-2018-14438 | — | — | 1.2% | Jul 20, 2018 | In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl ... |
| CVE-2018-14437 | — | — | 2.1% | Jul 20, 2018 | ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c. |
| CVE-2018-14436 | — | — | 2.1% | Jul 20, 2018 | ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c. |
| CVE-2018-14435 | — | — | 2.1% | Jul 20, 2018 | ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c. |
| CVE-2018-14434 | — | — | 2.8% | Jul 20, 2018 | ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c. |
| CVE-2018-14336 | — | — | 8.3% | Jul 19, 2018 | TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w... |
| CVE-2018-12959 | — | — | 0.9% | Jul 19, 2018 | The approveAndCall function of a smart contract implementation for Aditus (ADI), an Ethereum ERC20 token, allows attacke... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now