2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11009HIGH7.8A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
CVE-2018-11008MEDIUM5.5An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
CVE-2018-11007MEDIUM5.5A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
CVE-2018-11006MEDIUM5.5An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
CVE-2018-11005MEDIUM5.5A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
CVE-2018-20316HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can ca...
CVE-2018-20315HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-ba...
CVE-2018-20314HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that ca...
CVE-2018-20313HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that c...
CVE-2018-18689MEDIUM5.3The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of ho...
CVE-2018-18688MEDIUM5.3The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of ho...
CVE-2018-20312HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can ca...
CVE-2018-20311HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can ...
CVE-2018-20310HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can ca...
CVE-2018-20309HIGH8.1Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that c...
CVE-2018-19418HIGH7.8Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security perm...
CVE-2018-25002HIGH8.8uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-201...
CVE-2018-19945CRITICAL9.1A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitati...
CVE-2018-19944HIGH7.5A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If expl...
CVE-2018-19941HIGH7.5A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sens...
CVE-2018-25001MEDIUM6.5An issue was discovered in the libpulse-binding crate before 2.5.0 for Rust. proplist::Iterator can cause a use-after-fr...
CVE-2018-16795HIGH8.8OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of...
CVE-2018-14067CRITICAL9.8Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command executio...
CVE-2018-1000893HIGH7.5Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.
CVE-2018-1000892HIGH7.5Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now