2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0982An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows...
CVE-2018-0978A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet...
CVE-2018-0871An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclos...
CVE-2018-12355MEDIUM6.1Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue...
CVE-2018-12354Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analytic...
CVE-2018-12353Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
CVE-2018-12271An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) val...
CVE-2018-12019The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not ...
CVE-2018-0495Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be...
CVE-2018-12040Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attacke...
CVE-2018-10408An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing che...
CVE-2018-10407An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party co...
CVE-2018-10406An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code sign...
CVE-2018-10405An issue was discovered in Google Santa and molcodesignchecker. A maliciously crafted Universal/fat binary can evade thi...
CVE-2018-10404An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously craf...
CVE-2018-10403An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade thir...
CVE-2018-5488NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30...
CVE-2018-1121LOW3.9procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() return...
CVE-2018-10850MEDIUM5.9389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persisten...
CVE-2018-12339ArticleCMS through 2017-02-19 has XSS via an "add an article" action.
CVE-2018-7559An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET L...
CVE-2018-10363An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multi...
CVE-2018-7167HIGH7.5Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Servic...
CVE-2018-7164HIGH7.5Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases...
CVE-2018-7162HIGH7.5All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now