2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-4216——A logic issue existed in the handling of call URLs. This issue was addressed with improved state management. This issue ...
CVE-2018-4203——An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12, macOS M...
CVE-2018-4197——A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS...
CVE-2018-4195——An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to...
CVE-2018-4191——A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12,...
CVE-2018-4178——A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved ...
CVE-2018-4153——An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
CVE-2018-4145——Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO...
CVE-2018-4126——A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, mac...
CVE-2018-20506——SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow)...
CVE-2018-20505——SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial o...
CVE-2018-18035——A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to co...
CVE-2018-12680——The Serialize.deserialize() method in CoAPthon 3.1, 4.0.0, 4.0.1, and 4.0.2 mishandles certain exceptions, leading to a ...
CVE-2018-12679——The Serialize.deserialize() method in CoAPthon3 1.0 and 1.0.1 mishandles certain exceptions, leading to a denial of serv...
CVE-2018-19275——The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, whic...
CVE-2018-15180——qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.
CVE-2018-19113——The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)...
CVE-2018-17990——An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp ...
CVE-2018-17989——A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authent...
CVE-2018-17565——Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows att...
CVE-2018-17564——A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete c...
CVE-2018-17563——A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers t...
CVE-2018-5757——An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functi...
CVE-2018-18766——An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905.
CVE-2018-19201——A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaSc...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now