2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18880——In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS)...
CVE-2018-18879——In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to...
CVE-2018-20013——In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin...
CVE-2018-18958——OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
CVE-2018-19450——A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a la...
CVE-2018-19449——A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja...
CVE-2018-19448——In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHa...
CVE-2018-19447——A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when pa...
CVE-2018-19446——A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja...
CVE-2018-19445——A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when...
CVE-2018-19444——A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF fil...
CVE-2018-19146——Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTM...
CVE-2018-10239——A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a lo...
CVE-2018-20468——An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" th...
CVE-2018-6350——An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects Wha...
CVE-2018-6339——When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data bei...
CVE-2018-5913——A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto,...
CVE-2018-5911——Buffer overflow in WLAN function due to improper check of buffer size before copying in Snapdragon Auto, Snapdragon Cons...
CVE-2018-5903——Out of bounds read occurs due to improper validation of array while processing VDEV stop response from WLAN firmware in ...
CVE-2018-5883——Buffer overflow in WLAN driver event handlers due to improper validation of array index in Snapdragon Auto, Snapdragon C...
CVE-2018-3583——A buffer overflow can occur while processing an extscan hotlist event in Snapdragon Auto, Snapdragon Consumer Electronic...
CVE-2018-13919——Use-after-free vulnerability will occur if reset of the routing table encounters an invalid rule id while processing com...
CVE-2018-13911——Out of bounds memory read and access may lead to unexpected behavior in GNSS XTRA Parser in Snapdragon Auto, Snapdragon ...
CVE-2018-13910——Out-of-Bounds access in TZ due to invalid index calculated to check against DDR in Snapdragon Auto, Snapdragon Connectiv...
CVE-2018-13909——Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing state in progress resulti...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now