2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3945 | HIGH | 8.8 | 3.2% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3942 | HIGH | 8.8 | 3.2% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.... |
| CVE-2018-3941 | HIGH | 8.8 | 3.2% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3940 | HIGH | 8.8 | 2.1% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.... |
| CVE-2018-17443 | — | — | 5.7% | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS... |
| CVE-2018-17442 | — | — | 14.2% | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerabili... |
| CVE-2018-17441 | — | — | 5.7% | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser... |
| CVE-2018-17440 | — | — | 36.9% | Oct 8, 2018 | An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b... |
| CVE-2018-17060 | MEDIUM | 5.3 | 1.0% | Oct 8, 2018 | Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to acce... |
| CVE-2018-16297 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16296 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16295 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16294 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16293 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16292 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-16291 | — | — | 2.7% | Oct 8, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF be... |
| CVE-2018-5402 | CRITICAL | 9.1 | 0.9% | Oct 8, 2018 | The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted p... |
| CVE-2018-5401 | CRITICAL | 9.1 | 0.9% | Oct 8, 2018 | The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in c... |
| CVE-2018-5400 | CRITICAL | 9.1 | 0.7% | Oct 8, 2018 | The Auto-Maskin products utilize an undocumented custom protocol to set up Modbus communications with other devices with... |
| CVE-2018-5399 | CRITICAL | 9.4 | 2.1% | Oct 8, 2018 | The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 2... |
| CVE-2018-1753 | MEDIUM | 4.3 | 1.0% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about ... |
| CVE-2018-1750 | MEDIUM | 4.2 | 0.7% | Oct 8, 2018 | IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that ... |
| CVE-2018-1749 | MEDIUM | 4.3 | 0.9% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 uses incomplete blacklisting for input validation which allows attack... |
| CVE-2018-1743 | MEDIUM | 5.3 | 1.3% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 discloses sensitive information to unauthorized users. The informatio... |
| CVE-2018-1742 | MEDIUM | 5.9 | 0.3% | Oct 8, 2018 | IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now