2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-4931 | — | — | 1.9% | May 19, 2018 | Adobe Experience Manager versions 6.1 and earlier have an exploitable stored cross-site scripting vulnerability. Success... |
| CVE-2018-4930 | — | — | 1.9% | May 19, 2018 | Adobe Experience Manager versions 6.3 and earlier have an exploitable Cross-site scripting vulnerability. Successful exp... |
| CVE-2018-4929 | — | — | 1.9% | May 19, 2018 | Adobe Experience Manager versions 6.2 and earlier have an exploitable stored cross-site scripting vulnerability. Success... |
| CVE-2018-4928 | — | — | 4.4% | May 19, 2018 | Adobe InDesign versions 13.0 and below have an exploitable Memory corruption vulnerability. Successful exploitation coul... |
| CVE-2018-4927 | — | — | 3.7% | May 19, 2018 | Adobe InDesign versions 13.0 and below have an exploitable Untrusted Search Path vulnerability. Successful exploitation ... |
| CVE-2018-4926 | — | — | 6.2% | May 19, 2018 | Adobe Digital Editions versions 4.5.7 and below have an exploitable Stack Overflow vulnerability. Successful exploitatio... |
| CVE-2018-4925 | — | — | 4.0% | May 19, 2018 | Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploit... |
| CVE-2018-4924 | — | — | 14.5% | May 19, 2018 | Adobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. Successful exploitation could... |
| CVE-2018-4923 | — | — | 9.5% | May 19, 2018 | Adobe Connect versions 9.7 and earlier have an exploitable OS Command Injection. Successful exploitation could lead to a... |
| CVE-2018-4921 | — | — | 4.2% | May 19, 2018 | Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploi... |
| CVE-2018-4873 | — | — | 1.3% | May 19, 2018 | Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Unquoted Search Path vulnera... |
| CVE-2018-1148 | — | — | 0.8% | May 18, 2018 | In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authen... |
| CVE-2018-1147 | — | — | 1.1% | May 18, 2018 | In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker cou... |
| CVE-2018-8867 | — | — | 3.5% | May 18, 2018 | In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 a... |
| CVE-2018-6562 | — | — | 0.7% | May 18, 2018 | totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user session... |
| CVE-2018-11256 | — | — | 1.4% | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows re... |
| CVE-2018-11255 | — | — | 1.1% | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows rem... |
| CVE-2018-11254 | — | — | 1.1% | May 18, 2018 | An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of ... |
| CVE-2018-11251 | — | — | 2.1% | May 18, 2018 | In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, w... |
| CVE-2018-11248 | — | — | 2.1% | May 18, 2018 | util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in ... |
| CVE-2018-11245 | — | — | 0.9% | May 18, 2018 | app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes. |
| CVE-2018-1000400 | — | — | 2.1% | May 18, 2018 | Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handli... |
| CVE-2018-8015 | — | — | 3.5% | May 18, 2018 | In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java pa... |
| CVE-2018-11244 | — | — | 1.0% | May 18, 2018 | The BBE theme before 1.53 for WordPress allows a direct launch of an HTML editor. |
| CVE-2018-11243 | — | — | 2.5% | May 18, 2018 | PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), l... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now