2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-9151A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel dri...
CVE-2018-9148Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it e...
CVE-2018-3740A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a wh...
CVE-2018-3728hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulner...
CVE-2018-9147Cross-site scripting (XSS) vulnerabilities in version 7.5.7 of Gespage software allow remote attackers to inject arbitra...
CVE-2018-9134file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file ...
CVE-2018-5799In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /ap...
CVE-2018-9146Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17724. Reason: This candidate is a reservation...
CVE-2018-9145In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer...
CVE-2018-9144In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial...
CVE-2018-9143On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code...
CVE-2018-9142On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area...
CVE-2018-9141On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary...
CVE-2018-9140On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary fi...
CVE-2018-9139On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privi...
CVE-2018-9138An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion ...
CVE-2018-9136windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafte...
CVE-2018-9135In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.
CVE-2018-9133ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), whi...
CVE-2018-9132libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leve...
CVE-2018-9130IBOS 4.4.3 has XSS via a company full name.
CVE-2018-1191Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access ...
CVE-2018-9031The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd =="...
CVE-2018-5224Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating syst...
CVE-2018-5223Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now