2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10193LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document...
CVE-2018-8838A weakness in access controls in CENTUM CS 1000 all versions, CENTUM CS 3000 versions R3.09.50 and earlier, CENTUM CS 30...
CVE-2018-10192IPVanish 3.0.11 for macOS suffers from a root privilege escalation vulnerability. The `com.ipvanish.osx.vpnhelper` Launc...
CVE-2018-10191CRITICAL9.8In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_G...
CVE-2018-7539On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted ...
CVE-2018-6913Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbi...
CVE-2018-6798An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a he...
CVE-2018-6797An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, ...
CVE-2018-10190A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenti...
CVE-2018-10189An issue was discovered in Mautic 1.x and 2.x before 2.13.0. It is possible to systematically emulate tracking cookies p...
CVE-2018-10187In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote a...
CVE-2018-10186In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attacke...
CVE-2018-8834HIGH7.8Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet ...
CVE-2018-7530Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet ...
CVE-2018-7514HIGH7.8Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet ...
CVE-2018-10185An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated ...
CVE-2018-5431MEDIUM6.3The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community ...
CVE-2018-5430HIGH8.8The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, ...
CVE-2018-5429HIGH8.8A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperRepor...
CVE-2018-1445IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2018-1371An IBM WebSphere MQ 8.0.0.8, 9.0.0.2, and 9.0.4 Client connecting to a MQ Queue Manager can cause a SIGSEGV in the AMQRM...
CVE-2018-10183An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php ...
CVE-2018-5190PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer account...
CVE-2018-10178MEDIUM5.3The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via ve...
CVE-2018-10177In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote atta...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now