2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-21260 | LOW | 2.7 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent dur... |
| CVE-2018-21259 | MEDIUM | 5.3 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of s... |
| CVE-2018-21258 | HIGH | 7.5 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite... |
| CVE-2018-21257 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for... |
| CVE-2018-21255 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to mod... |
| CVE-2018-21254 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-mess... |
| CVE-2018-21253 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slas... |
| CVE-2018-21251 | CRITICAL | 9.8 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name w... |
| CVE-2018-21250 | MEDIUM | 6.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a deni... |
| CVE-2018-21249 | LOW | 3.7 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing. |
| CVE-2018-21248 | HIGH | 7.5 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication creden... |
| CVE-2018-21247 | HIGH | 7.5 | 2.4% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) i... |
| CVE-2018-21246 | CRITICAL | 9.8 | 2.7% | Jun 15, 2020 | Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lac... |
| CVE-2018-21245 | CRITICAL | 9.1 | 1.1% | Jun 15, 2020 | Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711. |
| CVE-2018-16848 | MEDIUM | 6.5 | 1.2% | Jun 15, 2020 | A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a... |
| CVE-2018-21244 | CRITICAL | 9.8 | 1.8% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded exec... |
| CVE-2018-21243 | MEDIUM | 6.5 | 0.9% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used. |
| CVE-2018-21242 | CRITICAL | 9.8 | 2.2% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows Remote Code Execution via a GoToE or GoToR action. |
| CVE-2018-21241 | HIGH | 7.8 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.6. It has an untrusted search path that allows a DLL to execute r... |
| CVE-2018-21240 | HIGH | 7.5 | 1.0% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfff... |
| CVE-2018-21239 | MEDIUM | 5.3 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR ... |
| CVE-2018-21238 | HIGH | 7.5 | 1.0% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows memory consumption via an ArrayBuffer(0xfffffffe) ca... |
| CVE-2018-21237 | MEDIUM | 5.3 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action. |
| CVE-2018-21236 | HIGH | 7.5 | 1.0% | Jun 4, 2020 | An issue was discovered in Foxit Reader before 2.4.4. It has a NULL pointer dereference. |
| CVE-2018-21235 | HIGH | 7.5 | 1.2% | Jun 4, 2020 | An issue was discovered in Foxit E-mail advertising system before September 2018. It allows authentication bypass and in... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now