2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18500A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This result...
CVE-2018-8799rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that re...
CVE-2018-8798rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that result...
CVE-2018-8796rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that res...
CVE-2018-8792rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that result...
CVE-2018-8791rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in a...
CVE-2018-20252In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ...
CVE-2018-20251In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field o...
CVE-2018-19029LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a poin...
CVE-2018-19002LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially cra...
CVE-2018-19000LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sen...
CVE-2018-18998LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized acce...
CVE-2018-18996LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, wh...
CVE-2018-18992LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an ...
CVE-2018-18990LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation....
CVE-2018-18986LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may caus...
CVE-2018-15659An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications....
CVE-2018-15658An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master....
CVE-2018-15657An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
CVE-2018-15656An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a ...
CVE-2018-15655An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible.
CVE-2018-20752An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV inj...
CVE-2018-1000999Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: [CVE-2018-20323]. Reason: This candidate is a duplicate o...
CVE-2018-1000998FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited i...
CVE-2018-20751An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().Ad...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now