2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-3960HIGH7.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ...
CVE-2018-3959HIGH7.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ...
CVE-2018-3958HIGH7.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ...
CVE-2018-3957HIGH7.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. ...
CVE-2018-3944HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1....
CVE-2018-3943HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1....
CVE-2018-4001HIGH7.8An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of Atlantis Word Processor, vers...
CVE-2018-4000HIGH7.8An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5....
CVE-2018-3999HIGH7.8An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3...
CVE-2018-3998HIGH7.8An exploitable heap-based buffer overflow vulnerability exists in the Windows enhanced metafile parser of Atlantis Word ...
CVE-2018-3984HIGH7.8An exploitable uninitialized length vulnerability exists within the Word document-parser of the Atlantis Word Processor ...
CVE-2018-3982HIGH7.8An exploitable arbitrary write vulnerability exists in the Word document parser of the Atlantis Word Processor 3.0.2.3 a...
CVE-2018-3981HIGH7.8An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker ca...
CVE-2018-3978HIGH8.8An exploitable out-of-bounds write vulnerability exists in the Word Document parser of the Atlantis Word Processor 3.0.2...
CVE-2018-3975HIGH7.5An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3...
CVE-2018-17848HIGH7.5The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "...
CVE-2018-17847HIGH7.5The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading ...
CVE-2018-17846HIGH7.5The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading...
CVE-2018-1251HIGH8.3Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauth...
CVE-2018-1702HIGH7.1IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML Exter...
CVE-2018-14648HIGH7.5A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in th...
CVE-2018-1736HIGH7.4IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open red...
CVE-2018-17365HIGH7.5SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
CVE-2018-16364HIGH8.1A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execut...
CVE-2018-16152HIGH7.5In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the R...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now