2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6203 | — | — | 0.4% | Jan 25, 2018 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-6202 | — | — | 0.4% | Jan 25, 2018 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-6201 | — | — | 0.4% | Jan 25, 2018 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-6200 | — | — | 3.4% | Jan 25, 2018 | vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter. |
| CVE-2018-6198 | — | — | 0.4% | Jan 25, 2018 | w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local... |
| CVE-2018-6197 | — | — | 4.5% | Jan 25, 2018 | w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c. |
| CVE-2018-6196 | — | — | 3.0% | Jan 25, 2018 | w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in t... |
| CVE-2018-5445 | — | — | 1.9% | Jan 25, 2018 | A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read... |
| CVE-2018-5443 | — | — | 1.2% | Jan 25, 2018 | A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does ... |
| CVE-2018-1047 | — | — | 0.5% | Jan 24, 2018 | A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.Se... |
| CVE-2018-1000006 | — | — | 84.7% | Jan 24, 2018 | GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro... |
| CVE-2018-1000005 | — | — | 4.6% | Jan 24, 2018 | libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (ht... |
| CVE-2018-6193 | — | — | 2.2% | Jan 24, 2018 | A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph... |
| CVE-2018-6192 | — | — | 1.9% | Jan 24, 2018 | In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of s... |
| CVE-2018-6191 | — | — | 5.3% | Jan 24, 2018 | The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v... |
| CVE-2018-6190 | — | — | 1.6% | Jan 24, 2018 | Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page. |
| CVE-2018-5759 | — | — | 5.2% | Jan 24, 2018 | jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re... |
| CVE-2018-5705 | — | — | 1.5% | Jan 24, 2018 | Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to t... |
| CVE-2018-6018 | — | — | 1.0% | Jan 24, 2018 | Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive i... |
| CVE-2018-6017 | — | — | 1.0% | Jan 24, 2018 | Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensit... |
| CVE-2018-5778 | — | — | 1.1% | Jan 24, 2018 | An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities a... |
| CVE-2018-5777 | — | — | 1.7% | Jan 24, 2018 | An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a m... |
| CVE-2018-5319 | — | — | 12.6% | Jan 24, 2018 | RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request. |
| CVE-2018-1000018 | — | — | 0.4% | Jan 24, 2018 | An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file. |
| CVE-2018-6187 | — | — | 1.9% | Jan 24, 2018 | In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now