2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10193 | — | — | 4.8% | Apr 18, 2018 | LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document... |
| CVE-2018-8838 | — | — | 0.3% | Apr 17, 2018 | A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 30... |
| CVE-2018-10192 | — | — | 2.4% | Apr 17, 2018 | IPVanish 3.0.11 for macOS suffers from a root privilege escalation vulnerability. The `com.ipvanish.osx.vpnhelper` Launc... |
| CVE-2018-10191 | CRITICAL | 9.8 | 2.6% | Apr 17, 2018 | In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_G... |
| CVE-2018-7539 | — | — | 4.3% | Apr 17, 2018 | On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted ... |
| CVE-2018-6913 | — | — | 10.9% | Apr 17, 2018 | Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbi... |
| CVE-2018-6798 | — | — | 4.0% | Apr 17, 2018 | An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a he... |
| CVE-2018-6797 | — | — | 7.4% | Apr 17, 2018 | An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, ... |
| CVE-2018-10190 | — | — | 0.3% | Apr 17, 2018 | A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenti... |
| CVE-2018-10189 | — | — | 1.2% | Apr 17, 2018 | An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies p... |
| CVE-2018-10187 | — | — | 0.9% | Apr 17, 2018 | In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote a... |
| CVE-2018-10186 | — | — | 0.9% | Apr 17, 2018 | In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attacke... |
| CVE-2018-8834 | HIGH | 7.8 | 0.3% | Apr 17, 2018 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet ... |
| CVE-2018-7530 | — | — | 0.3% | Apr 17, 2018 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet ... |
| CVE-2018-7514 | HIGH | 7.8 | 0.3% | Apr 17, 2018 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet ... |
| CVE-2018-10185 | — | — | 0.5% | Apr 17, 2018 | An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated ... |
| CVE-2018-5431 | MEDIUM | 6.3 | 0.6% | Apr 17, 2018 | The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community ... |
| CVE-2018-5430 | HIGH | 8.8 | 48.8% | Apr 17, 2018 | The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, ... |
| CVE-2018-5429 | HIGH | 8.8 | 1.6% | Apr 17, 2018 | A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperRepor... |
| CVE-2018-1445 | — | — | 0.8% | Apr 17, 2018 | IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allow... |
| CVE-2018-1371 | — | — | 1.2% | Apr 17, 2018 | An IBM WebSphere MQ 8.0.0.8, 9.0.0.2, and 9.0.4 Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRM... |
| CVE-2018-10183 | — | — | 0.7% | Apr 17, 2018 | An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php ... |
| CVE-2018-5190 | — | — | 1.4% | Apr 17, 2018 | PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer account... |
| CVE-2018-10178 | MEDIUM | 5.3 | 1.1% | Apr 17, 2018 | The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via ve... |
| CVE-2018-10177 | — | — | 3.2% | Apr 16, 2018 | In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote atta... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now