2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10481 | MEDIUM | 6.5 | 2.5% | May 17, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-10480 | MEDIUM | 6.5 | 2.5% | May 17, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-10479 | MEDIUM | 6.5 | 2.5% | May 17, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-10478 | MEDIUM | 6.5 | 2.5% | May 17, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-10477 | — | — | 2.8% | May 17, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.2... |
| CVE-2018-10476 | MEDIUM | 6.5 | 2.5% | May 17, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-10475 | MEDIUM | 6.5 | 2.5% | May 17, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-10474 | — | — | 2.8% | May 17, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.2... |
| CVE-2018-10473 | — | — | 2.8% | May 17, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.2... |
| CVE-2018-7160 | HIGH | 8.8 | 9.9% | May 17, 2018 | The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remo... |
| CVE-2018-7159 | MEDIUM | 5.3 | 3.6% | May 17, 2018 | The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as... |
| CVE-2018-7158 | HIGH | 7.5 | 3.4% | May 17, 2018 | The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) ve... |
| CVE-2018-11120 | — | — | 0.9% | May 17, 2018 | Services/COPage/classes/class.ilPCSourceCode.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS. |
| CVE-2018-11119 | — | — | 0.9% | May 17, 2018 | ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parame... |
| CVE-2018-11118 | — | — | 1.3% | May 17, 2018 | The RSS subsystem in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a URI to Services/Feeds/classes/class.ilExte... |
| CVE-2018-11117 | — | — | 0.9% | May 17, 2018 | Services/Feeds/classes/class.ilExternalFeedItem.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a link att... |
| CVE-2018-11230 | — | — | 1.8% | May 17, 2018 | jbig2_add_page in jbig2enc.cc in libjbig2enc.a in jbig2enc 0.29 allows remote attackers to cause a denial of service (us... |
| CVE-2018-10027 | — | — | 0.4% | May 17, 2018 | ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installin... |
| CVE-2018-11226 | — | — | 1.7% | May 17, 2018 | The getString function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size g... |
| CVE-2018-11225 | — | — | 2.0% | May 17, 2018 | The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size grea... |
| CVE-2018-11224 | — | — | 1.0% | May 17, 2018 | An issue was discovered in Libav 12.3. A read access violation in the in_table_init16 function in libavcodec/aacsbr.c al... |
| CVE-2018-0328 | — | — | 1.8% | May 17, 2018 | A vulnerability in the web framework of Cisco Unified Communications Manager and Cisco Unified Presence could allow an u... |
| CVE-2018-0327 | — | — | 1.8% | May 17, 2018 | A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote atta... |
| CVE-2018-0326 | — | — | 1.8% | May 17, 2018 | A vulnerability in the web UI of Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to c... |
| CVE-2018-0325 | — | — | 3.4% | May 17, 2018 | A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 7800 Series phone... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now