2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3993 | HIGH | 8.8 | 3.2% | Oct 3, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3967 | HIGH | 7.8 | 6.2% | Oct 3, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3966 | HIGH | 7.8 | 6.2% | Oct 3, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3965 | HIGH | 7.8 | 6.0% | Oct 3, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3964 | HIGH | 7.8 | 9.5% | Oct 3, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3946 | HIGH | 8.8 | 3.2% | Oct 3, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader version 9.1.0... |
| CVE-2018-1794 | MEDIUM | 6.1 | 1.4% | Oct 3, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using OAuth ear is vulnerable to cross-site scripting. This vuln... |
| CVE-2018-1793 | MEDIUM | 6.1 | 1.4% | Oct 3, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using SAML ear is vulnerable to cross-site scripting. This vulne... |
| CVE-2018-14800 | — | — | 1.6% | Oct 3, 2018 | Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application... |
| CVE-2018-6689 | HIGH | 7.8 | 0.4% | Oct 3, 2018 | Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.... |
| CVE-2018-17947 | — | — | 1.2% | Oct 3, 2018 | The Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter. |
| CVE-2018-17946 | — | — | 0.8% | Oct 3, 2018 | The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Gallerye... |
| CVE-2018-17942 | — | — | 2.5% | Oct 3, 2018 | The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because mem... |
| CVE-2018-17938 | — | — | 0.6% | Oct 3, 2018 | Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value. |
| CVE-2018-3962 | HIGH | 7.3 | 2.5% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3961 | HIGH | 7.8 | 2.4% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3960 | HIGH | 7.8 | 2.4% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3959 | HIGH | 7.8 | 2.4% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3958 | HIGH | 7.8 | 2.9% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3957 | HIGH | 7.8 | 2.9% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3944 | HIGH | 8.8 | 2.6% | Oct 2, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.... |
| CVE-2018-3943 | HIGH | 8.8 | 2.6% | Oct 2, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.... |
| CVE-2018-14826 | — | — | 7.7% | Oct 2, 2018 | Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass ... |
| CVE-2018-14822 | — | — | 2.9% | Oct 2, 2018 | Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has... |
| CVE-2018-9515 | — | — | 0.7% | Oct 2, 2018 | In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now