2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18500——A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This result...
CVE-2018-8799——rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that re...
CVE-2018-8798——rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that result...
CVE-2018-8796——rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that res...
CVE-2018-8792——rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that result...
CVE-2018-8791——rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in a...
CVE-2018-20252——In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ...
CVE-2018-20251——In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field o...
CVE-2018-19029——LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a poin...
CVE-2018-19002——LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially cra...
CVE-2018-19000——LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sen...
CVE-2018-18998——LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized acce...
CVE-2018-18996——LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, wh...
CVE-2018-18992——LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an ...
CVE-2018-18990——LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation....
CVE-2018-18986——LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may caus...
CVE-2018-15659——An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications....
CVE-2018-15658——An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master....
CVE-2018-15657——An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
CVE-2018-15656——An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a ...
CVE-2018-15655——An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible.
CVE-2018-20752——An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV inj...
CVE-2018-1000999——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: [CVE-2018-20323]. Reason: This candidate is a duplicate o...
CVE-2018-1000998——FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited i...
CVE-2018-20751——An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().Ad...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now