2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3593 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon W... |
| CVE-2018-3592 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MD... |
| CVE-2018-3591 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MD... |
| CVE-2018-3590 | — | — | 1.3% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD ... |
| CVE-2018-3589 | — | — | 1.4% | Apr 11, 2018 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile MDM9650, MDM9655, SD 835, SD 845, SD 850... |
| CVE-2018-1275 | CRITICAL | 9.8 | 57.6% | Apr 11, 2018 | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow app... |
| CVE-2018-1273 | CRITICAL | 9.8 | 95.6% | Apr 11, 2018 | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property... |
| CVE-2018-9992 | — | — | 0.5% | Apr 11, 2018 | Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ scre... |
| CVE-2018-9991 | — | — | 0.5% | Apr 11, 2018 | Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter. |
| CVE-2018-7660 | — | — | 0.5% | Apr 11, 2018 | In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially b... |
| CVE-2018-7659 | — | — | 0.5% | Apr 11, 2018 | In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be e... |
| CVE-2018-10017 | MEDIUM | 6.5 | 2.2% | Apr 11, 2018 | soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial o... |
| CVE-2018-10016 | — | — | 1.1% | Apr 11, 2018 | Netwide Assembler (NASM) 2.14rc0 has a division-by-zero vulnerability in the expr5 function in asm/eval.c via a malforme... |
| CVE-2018-10001 | — | — | 2.4% | Apr 11, 2018 | The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of... |
| CVE-2018-10000 | — | — | 0.6% | Apr 11, 2018 | The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to... |
| CVE-2018-9996 | — | — | 1.3% | Apr 10, 2018 | An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in... |
| CVE-2018-9995 | — | — | 83.2% | Apr 10, 2018 | TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L... |
| CVE-2018-9993 | — | — | 0.5% | Apr 10, 2018 | YUNUCMS 1.0.7 has XSS via the content title on an admin/content/addcontent/cid/## page (aka a news center page). |
| CVE-2018-3839 | HIGH | 8.8 | 2.6% | Apr 10, 2018 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer ... |
| CVE-2018-3838 | MEDIUM | 6.5 | 1.8% | Apr 10, 2018 | An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL... |
| CVE-2018-3837 | MEDIUM | 5.5 | 1.2% | Apr 10, 2018 | An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedi... |
| CVE-2018-9989 | HIGH | 7.5 | 2.1% | Apr 10, 2018 | ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that co... |
| CVE-2018-9988 | HIGH | 7.5 | 2.1% | Apr 10, 2018 | ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() tha... |
| CVE-2018-9985 | — | — | 0.7% | Apr 10, 2018 | The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator. |
| CVE-2018-9918 | — | — | 1.7% | Apr 10, 2018 | libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing r... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now