2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-21260LOW2.7An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. WebSocket events were accidentally sent dur...
CVE-2018-21259MEDIUM5.3An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of s...
CVE-2018-21258HIGH7.5An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite...
CVE-2018-21257MEDIUM5.3An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for...
CVE-2018-21255MEDIUM4.3An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to mod...
CVE-2018-21254MEDIUM4.3An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-mess...
CVE-2018-21253MEDIUM4.3An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slas...
CVE-2018-21251CRITICAL9.8An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name w...
CVE-2018-21250MEDIUM6.5An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a deni...
CVE-2018-21249LOW3.7An issue was discovered in Mattermost Server before 5.3.0. It mishandles timing.
CVE-2018-21248HIGH7.5An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication creden...
CVE-2018-21247HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) i...
CVE-2018-21246CRITICAL9.8Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lac...
CVE-2018-21245CRITICAL9.1Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.
CVE-2018-16848MEDIUM6.5A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a...
CVE-2018-21244CRITICAL9.8An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded exec...
CVE-2018-21243MEDIUM6.5An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used.
CVE-2018-21242CRITICAL9.8An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows Remote Code Execution via a GoToE or GoToR action.
CVE-2018-21241HIGH7.8An issue was discovered in Foxit PhantomPDF before 8.3.6. It has an untrusted search path that allows a DLL to execute r...
CVE-2018-21240HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfff...
CVE-2018-21239MEDIUM5.3An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR ...
CVE-2018-21238HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows memory consumption via an ArrayBuffer(0xfffffffe) ca...
CVE-2018-21237MEDIUM5.3An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action.
CVE-2018-21236HIGH7.5An issue was discovered in Foxit Reader before 2.4.4. It has a NULL pointer dereference.
CVE-2018-21235HIGH7.5An issue was discovered in Foxit E-mail advertising system before September 2018. It allows authentication bypass and in...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now