2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10508 | — | — | 1.3% | Jun 12, 2018 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to eleva... |
| CVE-2018-10507 | — | — | 1.4% | Jun 12, 2018 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or ... |
| CVE-2018-5814 | — | — | 0.4% | Jun 12, 2018 | In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling ... |
| CVE-2018-5803 | — | — | 0.5% | Jun 12, 2018 | In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_ch... |
| CVE-2018-5718 | — | — | 0.3% | Jun 12, 2018 | Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft Sy... |
| CVE-2018-12248 | — | — | 1.6% | Jun 12, 2018 | An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/... |
| CVE-2018-12247 | — | — | 1.6% | Jun 12, 2018 | An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class, related to certain .clone usag... |
| CVE-2018-12232 | — | — | 6.6% | Jun 12, 2018 | In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where ... |
| CVE-2018-12229 | — | — | 1.8% | Jun 12, 2018 | Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 al... |
| CVE-2018-12228 | — | — | 6.8% | Jun 12, 2018 | An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the clien... |
| CVE-2018-12227 | — | — | 3.5% | Jun 12, 2018 | An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Cert... |
| CVE-2018-6968 | — | — | 5.1% | Jun 11, 2018 | The VMware AirWatch Agent for Android prior to 8.2 and AirWatch Agent for Windows Mobile prior to 6.5.2 contain a remote... |
| CVE-2018-5185 | — | — | 1.6% | Jun 11, 2018 | Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbi... |
| CVE-2018-5184 | — | — | 1.8% | Jun 11, 2018 | Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbi... |
| CVE-2018-5183 | — | — | 3.2% | Jun 11, 2018 | Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues inclu... |
| CVE-2018-5182 | — | — | 2.1% | Jun 11, 2018 | If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the a... |
| CVE-2018-5181 | — | — | 2.5% | Jun 11, 2018 | If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process... |
| CVE-2018-5180 | — | — | 2.3% | Jun 11, 2018 | A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash,... |
| CVE-2018-5178 | — | — | 5.1% | Jun 11, 2018 | A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of d... |
| CVE-2018-5177 | — | — | 3.9% | Jun 11, 2018 | A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances,... |
| CVE-2018-5176 | — | — | 1.4% | Jun 11, 2018 | The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If ... |
| CVE-2018-5175 | — | — | 1.5% | Jun 11, 2018 | A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dyn... |
| CVE-2018-5174 | — | — | 1.9% | Jun 11, 2018 | In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with ... |
| CVE-2018-5173 | — | — | 1.8% | Jun 11, 2018 | The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name t... |
| CVE-2018-5172 | — | — | 1.6% | Jun 11, 2018 | The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard in... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now