2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000207 | — | — | 64.9% | Jul 13, 2018 | MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before pa... |
| CVE-2018-1000206 | — | — | 0.8% | Jul 13, 2018 | JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that... |
| CVE-2018-7535 | — | — | 0.3% | Jul 13, 2018 | An issue was discovered in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files bec... |
| CVE-2018-14054 | — | — | 2.6% | Jul 13, 2018 | A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again... |
| CVE-2018-1255 | MEDIUM | 6.1 | 1.3% | Jul 13, 2018 | RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains a reflected cross-site scripting vulnerab... |
| CVE-2018-1245 | CRITICAL | 9 | 2.5% | Jul 13, 2018 | RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability wit... |
| CVE-2018-10098 | — | — | 0.3% | Jul 13, 2018 | In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-priv... |
| CVE-2018-10018 | — | — | 6.3% | Jul 13, 2018 | The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo... |
| CVE-2018-9070 | — | — | 0.3% | Jul 13, 2018 | For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart ... |
| CVE-2018-9067 | — | — | 1.1% | Jul 13, 2018 | The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, i... |
| CVE-2018-14052 | — | — | 1.2% | Jul 13, 2018 | An issue has been found in libwav through 2017-04-20. It is a SEGV in the function apply_gain in wav_gain/wav_gain.c. |
| CVE-2018-14051 | — | — | 1.7% | Jul 13, 2018 | The function wav_read in libwav.c in libwav through 2017-04-20 has an infinite loop. |
| CVE-2018-14050 | — | — | 1.2% | Jul 13, 2018 | An issue has been found in libwav through 2017-04-20. It is a SEGV in the function wav_free in libwav.c. |
| CVE-2018-14049 | — | — | 1.2% | Jul 13, 2018 | An issue has been found in libwav through 2017-04-20. It is a SEGV in the function print_info in wav_info/wav_info.c. |
| CVE-2018-14048 | MEDIUM | 6.5 | 3.0% | Jul 13, 2018 | An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommende... |
| CVE-2018-14047 | — | — | 0.9% | Jul 13, 2018 | An issue has been found in PNGwriter 0.7.0. It is a SEGV in pngwriter::readfromfile in pngwriter.cc. NOTE: there is a "W... |
| CVE-2018-14046 | — | — | 1.7% | Jul 13, 2018 | Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp. |
| CVE-2018-14045 | — | — | 2.6% | Jul 13, 2018 | The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows... |
| CVE-2018-14044 | — | — | 2.6% | Jul 13, 2018 | The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allo... |
| CVE-2018-14043 | — | — | 1.7% | Jul 13, 2018 | mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_ac... |
| CVE-2018-14042 | — | — | 4.0% | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. |
| CVE-2018-14041 | — | — | 4.3% | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy. |
| CVE-2018-14040 | — | — | 4.1% | Jul 13, 2018 | In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute. |
| CVE-2018-6969 | — | — | 0.4% | Jul 13, 2018 | VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitatio... |
| CVE-2018-14036 | — | — | 3.1% | Jul 13, 2018 | Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now