2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18500 | — | — | 12.7% | Feb 5, 2019 | A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This result... |
| CVE-2018-8799 | — | — | 4.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that re... |
| CVE-2018-8798 | — | — | 3.8% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that result... |
| CVE-2018-8796 | — | — | 4.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that res... |
| CVE-2018-8792 | — | — | 4.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that result... |
| CVE-2018-8791 | — | — | 3.8% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in a... |
| CVE-2018-20252 | — | — | 3.6% | Feb 5, 2019 | In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ... |
| CVE-2018-20251 | — | — | 31.5% | Feb 5, 2019 | In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field o... |
| CVE-2018-19029 | — | — | 2.7% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a poin... |
| CVE-2018-19002 | — | — | 2.7% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially cra... |
| CVE-2018-19000 | — | — | 8.8% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sen... |
| CVE-2018-18998 | — | — | 2.4% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized acce... |
| CVE-2018-18996 | — | — | 2.5% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, wh... |
| CVE-2018-18992 | — | — | 2.0% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an ... |
| CVE-2018-18990 | — | — | 39.5% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation.... |
| CVE-2018-18986 | — | — | 2.7% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may caus... |
| CVE-2018-15659 | — | — | 1.4% | Feb 5, 2019 | An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications.... |
| CVE-2018-15658 | — | — | 1.8% | Feb 5, 2019 | An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.... |
| CVE-2018-15657 | — | — | 1.6% | Feb 5, 2019 | An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter. |
| CVE-2018-15656 | — | — | 1.6% | Feb 5, 2019 | An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a ... |
| CVE-2018-15655 | — | — | 1.4% | Feb 5, 2019 | An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible. |
| CVE-2018-20752 | — | — | 3.4% | Feb 4, 2019 | An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV inj... |
| CVE-2018-1000999 | — | — | — | Feb 4, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: [CVE-2018-20323]. Reason: This candidate is a duplicate o... |
| CVE-2018-1000998 | — | — | 0.9% | Feb 4, 2019 | FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited i... |
| CVE-2018-20751 | — | — | 1.6% | Feb 4, 2019 | An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().Ad... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now