2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-10508A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to eleva...
CVE-2018-10507A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or ...
CVE-2018-5814In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling ...
CVE-2018-5803In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_ch...
CVE-2018-5718Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft Sy...
CVE-2018-12248An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/...
CVE-2018-12247An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class, related to certain .clone usag...
CVE-2018-12232In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where ...
CVE-2018-12229Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 al...
CVE-2018-12228An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the clien...
CVE-2018-12227An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Cert...
CVE-2018-6968The VMware AirWatch Agent for Android prior to 8.2 and AirWatch Agent for Windows Mobile prior to 6.5.2 contain a remote...
CVE-2018-5185Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbi...
CVE-2018-5184Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbi...
CVE-2018-5183Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues inclu...
CVE-2018-5182If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the a...
CVE-2018-5181If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process...
CVE-2018-5180A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash,...
CVE-2018-5178A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of d...
CVE-2018-5177A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances,...
CVE-2018-5176The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If ...
CVE-2018-5175A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dyn...
CVE-2018-5174In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with ...
CVE-2018-5173The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name t...
CVE-2018-5172The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard in...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now