2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3960 | HIGH | 7.8 | 2.4% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3959 | HIGH | 7.8 | 2.4% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3958 | HIGH | 7.8 | 2.9% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3957 | HIGH | 7.8 | 2.9% | Oct 2, 2018 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ... |
| CVE-2018-3944 | HIGH | 8.8 | 2.6% | Oct 2, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.... |
| CVE-2018-3943 | HIGH | 8.8 | 2.6% | Oct 2, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.... |
| CVE-2018-4001 | HIGH | 7.8 | 1.5% | Oct 1, 2018 | An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of Atlantis Word Processor, vers... |
| CVE-2018-4000 | HIGH | 7.8 | 1.0% | Oct 1, 2018 | An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.... |
| CVE-2018-3999 | HIGH | 7.8 | 0.9% | Oct 1, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3... |
| CVE-2018-3998 | HIGH | 7.8 | 1.0% | Oct 1, 2018 | An exploitable heap-based buffer overflow vulnerability exists in the Windows enhanced metafile parser of Atlantis Word ... |
| CVE-2018-3984 | HIGH | 7.8 | 1.4% | Oct 1, 2018 | An exploitable uninitialized length vulnerability exists within the Word document-parser of the Atlantis Word Processor ... |
| CVE-2018-3982 | HIGH | 7.8 | 1.3% | Oct 1, 2018 | An exploitable arbitrary write vulnerability exists in the Word document parser of the Atlantis Word Processor 3.0.2.3 a... |
| CVE-2018-3981 | HIGH | 7.8 | 2.3% | Oct 1, 2018 | An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker ca... |
| CVE-2018-3978 | HIGH | 8.8 | 1.0% | Oct 1, 2018 | An exploitable out-of-bounds write vulnerability exists in the Word Document parser of the Atlantis Word Processor 3.0.2... |
| CVE-2018-3975 | HIGH | 7.5 | 1.2% | Oct 1, 2018 | An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3... |
| CVE-2018-17848 | HIGH | 7.5 | 2.7% | Oct 1, 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "... |
| CVE-2018-17847 | HIGH | 7.5 | 2.8% | Oct 1, 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading ... |
| CVE-2018-17846 | HIGH | 7.5 | 2.6% | Oct 1, 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading... |
| CVE-2018-1251 | HIGH | 8.3 | 2.5% | Sep 28, 2018 | Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauth... |
| CVE-2018-1702 | HIGH | 7.1 | 1.9% | Sep 28, 2018 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML Exter... |
| CVE-2018-14648 | HIGH | 7.5 | 6.2% | Sep 28, 2018 | A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in th... |
| CVE-2018-1736 | HIGH | 7.4 | 1.5% | Sep 27, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open red... |
| CVE-2018-17365 | HIGH | 7.5 | 2.1% | Sep 26, 2018 | SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter. |
| CVE-2018-16364 | HIGH | 8.1 | 15.1% | Sep 26, 2018 | A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execut... |
| CVE-2018-16152 | HIGH | 7.5 | 1.9% | Sep 26, 2018 | In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the R... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now