2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5967 | — | — | 0.7% | Jan 25, 2018 | Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page. |
| CVE-2018-6209 | — | — | 0.4% | Jan 25, 2018 | In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxCryptMon.sys) allows local users to cause a denial of service ... |
| CVE-2018-6208 | — | — | 0.4% | Jan 25, 2018 | In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of servi... |
| CVE-2018-6207 | — | — | 0.4% | Jan 25, 2018 | In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of servi... |
| CVE-2018-6206 | — | — | 0.4% | Jan 25, 2018 | In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of servi... |
| CVE-2018-6205 | — | — | 0.4% | Jan 25, 2018 | In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of servi... |
| CVE-2018-6204 | — | — | 0.4% | Jan 25, 2018 | In Max Secure Anti Virus 19.0.3.019,, the driver file (SDActMon.sys) allows local users to cause a denial of service (BS... |
| CVE-2018-6203 | — | — | 0.4% | Jan 25, 2018 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-6202 | — | — | 0.4% | Jan 25, 2018 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-6201 | — | — | 0.4% | Jan 25, 2018 | In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-6200 | — | — | 3.4% | Jan 25, 2018 | vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter. |
| CVE-2018-6198 | — | — | 0.4% | Jan 25, 2018 | w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local... |
| CVE-2018-6197 | — | — | 4.5% | Jan 25, 2018 | w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c. |
| CVE-2018-6196 | — | — | 3.0% | Jan 25, 2018 | w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in t... |
| CVE-2018-5445 | — | — | 1.9% | Jan 25, 2018 | A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read... |
| CVE-2018-5443 | — | — | 1.2% | Jan 25, 2018 | A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does ... |
| CVE-2018-1048 | HIGH | 7.5 | 1.6% | Jan 24, 2018 | It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH ... |
| CVE-2018-1047 | — | — | 0.5% | Jan 24, 2018 | A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.Se... |
| CVE-2018-1000006 | — | — | 84.7% | Jan 24, 2018 | GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro... |
| CVE-2018-1000007 | CRITICAL | 9.8 | 8.0% | Jan 24, 2018 | libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom heade... |
| CVE-2018-1000005 | — | — | 4.6% | Jan 24, 2018 | libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (ht... |
| CVE-2018-6193 | — | — | 2.2% | Jan 24, 2018 | A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph... |
| CVE-2018-6192 | — | — | 1.9% | Jan 24, 2018 | In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of s... |
| CVE-2018-6191 | — | — | 5.3% | Jan 24, 2018 | The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v... |
| CVE-2018-6190 | — | — | 1.6% | Jan 24, 2018 | Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now