2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18880In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS)...
CVE-2018-18879In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to...
CVE-2018-20013In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin...
CVE-2018-18958OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
CVE-2018-19450A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a la...
CVE-2018-19449A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja...
CVE-2018-19448In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHa...
CVE-2018-19447A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when pa...
CVE-2018-19446A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja...
CVE-2018-19445A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when...
CVE-2018-19444A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF fil...
CVE-2018-19146Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTM...
CVE-2018-10239A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a lo...
CVE-2018-20468An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" th...
CVE-2018-6350An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects Wha...
CVE-2018-6339When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data bei...
CVE-2018-5913A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto,...
CVE-2018-5911Buffer overflow in WLAN function due to improper check of buffer size before copying in Snapdragon Auto, Snapdragon Cons...
CVE-2018-5903Out of bounds read occurs due to improper validation of array while processing VDEV stop response from WLAN firmware in ...
CVE-2018-5883Buffer overflow in WLAN driver event handlers due to improper validation of array index in Snapdragon Auto, Snapdragon C...
CVE-2018-3583A buffer overflow can occur while processing an extscan hotlist event in Snapdragon Auto, Snapdragon Consumer Electronic...
CVE-2018-13919Use-after-free vulnerability will occur if reset of the routing table encounters an invalid rule id while processing com...
CVE-2018-13911Out of bounds memory read and access may lead to unexpected behavior in GNSS XTRA Parser in Snapdragon Auto, Snapdragon ...
CVE-2018-13910Out-of-Bounds access in TZ due to invalid index calculated to check against DDR in Snapdragon Auto, Snapdragon Connectiv...
CVE-2018-13909Metadata verification and partial hash system calls by bootloader may corrupt parallel hashing state in progress resulti...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now