2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-4216 | — | — | 0.7% | Apr 3, 2019 | A logic issue existed in the handling of call URLs. This issue was addressed with improved state management. This issue ... |
| CVE-2018-4203 | — | — | 1.5% | Apr 3, 2019 | An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12, macOS M... |
| CVE-2018-4197 | — | — | 9.4% | Apr 3, 2019 | A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS... |
| CVE-2018-4195 | — | — | 1.0% | Apr 3, 2019 | An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to... |
| CVE-2018-4191 | — | — | 2.2% | Apr 3, 2019 | A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12,... |
| CVE-2018-4178 | — | — | 0.3% | Apr 3, 2019 | A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved ... |
| CVE-2018-4153 | — | — | 0.9% | Apr 3, 2019 | An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14. |
| CVE-2018-4145 | — | — | 2.1% | Apr 3, 2019 | Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO... |
| CVE-2018-4126 | — | — | 1.9% | Apr 3, 2019 | A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, mac... |
| CVE-2018-20506 | — | — | 7.5% | Apr 3, 2019 | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow)... |
| CVE-2018-20505 | — | — | 6.8% | Apr 3, 2019 | SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial o... |
| CVE-2018-18035 | — | — | 1.2% | Apr 2, 2019 | A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to co... |
| CVE-2018-12680 | — | — | 1.5% | Apr 2, 2019 | The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a ... |
| CVE-2018-12679 | — | — | 1.4% | Apr 2, 2019 | The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of serv... |
| CVE-2018-19275 | — | — | 4.6% | Apr 2, 2019 | The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, whic... |
| CVE-2018-15180 | — | — | 0.8% | Apr 2, 2019 | qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter. |
| CVE-2018-19113 | — | — | 0.8% | Apr 1, 2019 | The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)... |
| CVE-2018-17990 | — | — | 4.5% | Apr 1, 2019 | An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp ... |
| CVE-2018-17989 | — | — | 0.8% | Apr 1, 2019 | A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authent... |
| CVE-2018-17565 | — | — | 1.9% | Apr 1, 2019 | Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows att... |
| CVE-2018-17564 | — | — | 1.6% | Apr 1, 2019 | A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete c... |
| CVE-2018-17563 | — | — | 0.7% | Apr 1, 2019 | A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers t... |
| CVE-2018-5757 | — | — | 7.8% | Apr 1, 2019 | An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functi... |
| CVE-2018-18766 | — | — | 1.2% | Mar 29, 2019 | An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905. |
| CVE-2018-19201 | — | — | 0.8% | Mar 29, 2019 | A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaSc... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now