2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18886MEDIUM6.1Helpy v2.1.0 has Stored XSS via the Ticket title.
CVE-2018-18880——In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS)...
CVE-2018-18879——In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to...
CVE-2018-20013——In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin...
CVE-2018-18958——OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
CVE-2018-19450——A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a la...
CVE-2018-19449——A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja...
CVE-2018-19448——In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHa...
CVE-2018-19447——A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when pa...
CVE-2018-19446——A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja...
CVE-2018-19445——A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when...
CVE-2018-19444——A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF fil...
CVE-2018-19146——Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTM...
CVE-2018-1845HIGH7.1IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack whe...
CVE-2018-10239——A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a lo...
CVE-2018-20472MEDIUM5.4An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
CVE-2018-20470HIGH7.5An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerab...
CVE-2018-20469CRITICAL9.8An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to...
CVE-2018-20468——An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" th...
CVE-2018-6350——An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects Wha...
CVE-2018-6349CRITICAL9.8When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for ...
CVE-2018-6339——When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data bei...
CVE-2018-5913——A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto,...
CVE-2018-5911——Buffer overflow in WLAN function due to improper check of buffer size before copying in Snapdragon Auto, Snapdragon Cons...
CVE-2018-5903——Out of bounds read occurs due to improper validation of array while processing VDEV stop response from WLAN firmware in ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now