2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-4216A logic issue existed in the handling of call URLs. This issue was addressed with improved state management. This issue ...
CVE-2018-4203An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12, macOS M...
CVE-2018-4197A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS...
CVE-2018-4195An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to...
CVE-2018-4191A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12,...
CVE-2018-4178A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved ...
CVE-2018-4153An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
CVE-2018-4145Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO...
CVE-2018-4126A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, mac...
CVE-2018-20506SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow)...
CVE-2018-20505SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial o...
CVE-2018-18035A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to co...
CVE-2018-12680The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a ...
CVE-2018-12679The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of serv...
CVE-2018-19275The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, whic...
CVE-2018-15180qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.
CVE-2018-19113The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)...
CVE-2018-17990An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp ...
CVE-2018-17989A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authent...
CVE-2018-17565Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows att...
CVE-2018-17564A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete c...
CVE-2018-17563A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers t...
CVE-2018-5757An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functi...
CVE-2018-18766An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905.
CVE-2018-19201A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaSc...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now