2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18886MEDIUM6.1Helpy v2.1.0 has Stored XSS via the Ticket title.
CVE-2018-18880In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS)...
CVE-2018-18879In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to...
CVE-2018-20013In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin...
CVE-2018-18958OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
CVE-2018-19450A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a la...
CVE-2018-19449A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja...
CVE-2018-19448In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHa...
CVE-2018-19447A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when pa...
CVE-2018-19446A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja...
CVE-2018-19445A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when...
CVE-2018-19444A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF fil...
CVE-2018-19146Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTM...
CVE-2018-1845HIGH7.1IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack whe...
CVE-2018-10239A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a lo...
CVE-2018-20472MEDIUM5.4An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
CVE-2018-20470HIGH7.5An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerab...
CVE-2018-20469CRITICAL9.8An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to...
CVE-2018-20468An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" th...
CVE-2018-6350An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects Wha...
CVE-2018-6349CRITICAL9.8When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for ...
CVE-2018-6339When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data bei...
CVE-2018-5913A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto,...
CVE-2018-5911Buffer overflow in WLAN function due to improper check of buffer size before copying in Snapdragon Auto, Snapdragon Cons...
CVE-2018-5903Out of bounds read occurs due to improper validation of array while processing VDEV stop response from WLAN firmware in ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now