2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18447CRITICAL9.8dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).
CVE-2018-18446CRITICAL9.8dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).
CVE-2018-25047MEDIUM5.4In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_f...
CVE-2018-5494Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-5483Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-14520MEDIUM5.4An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a u...
CVE-2018-14519MEDIUM4.3An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can c...
CVE-2018-1076Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-25045MEDIUM6.1Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view tem...
CVE-2018-25044HIGH8.8A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processin...
CVE-2018-25043HIGH8.8A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component P...
CVE-2018-25042HIGH8.8A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads ...
CVE-2018-25041HIGH8.8A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionali...
CVE-2018-25040HIGH8.8A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknow...
CVE-2018-18907HIGH7.5An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaini...
CVE-2018-25039MEDIUM5.4A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects ...
CVE-2018-25038MEDIUM5.4A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown p...
CVE-2018-25037MEDIUM5.4A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this issue is some unk...
CVE-2018-25036MEDIUM5.4A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerabilit...
CVE-2018-25035MEDIUM5.4A vulnerability, which was classified as problematic, was found in Thomson TCW710 ST5D.10.05. Affected is an unknown fun...
CVE-2018-25034MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Thomson TCW710 ST5D.10.05. This issue affects so...
CVE-2018-17240HIGH7.5There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacke...
CVE-2018-25033HIGH8.1ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenera...
CVE-2018-25030LOW2.5A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Af...
CVE-2018-25032HIGH7.5zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now