2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18886 | MEDIUM | 6.1 | 0.9% | Jun 18, 2019 | Helpy v2.1.0 has Stored XSS via the Ticket title. |
| CVE-2018-18880 | — | — | 0.9% | Jun 18, 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS)... |
| CVE-2018-18879 | — | — | 2.1% | Jun 18, 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to... |
| CVE-2018-20013 | — | — | 1.4% | Jun 18, 2019 | In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin... |
| CVE-2018-18958 | — | — | 0.6% | Jun 17, 2019 | OPNsense 18.7.x before 18.7.7 has Incorrect Access Control. |
| CVE-2018-19450 | — | — | 2.1% | Jun 17, 2019 | A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a la... |
| CVE-2018-19449 | — | — | 2.3% | Jun 17, 2019 | A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja... |
| CVE-2018-19448 | — | — | 2.2% | Jun 17, 2019 | In Foxit Reader SDK (ActiveX) Professional 5.4.0.1031, an uninitialized object in IReader_ContentProvider::GetDocEventHa... |
| CVE-2018-19447 | — | — | 4.9% | Jun 17, 2019 | A stack-based buffer overflow can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when pa... |
| CVE-2018-19446 | — | — | 2.2% | Jun 17, 2019 | A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the Ja... |
| CVE-2018-19445 | — | — | 2.6% | Jun 17, 2019 | A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when... |
| CVE-2018-19444 | — | — | 2.4% | Jun 17, 2019 | A use after free in the TextBox field Validate action in IReader_ContentProvider can occur for specially crafted PDF fil... |
| CVE-2018-19146 | — | — | 1.0% | Jun 17, 2019 | Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTM... |
| CVE-2018-1845 | HIGH | 7.1 | 2.0% | Jun 17, 2019 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack whe... |
| CVE-2018-10239 | — | — | 0.4% | Jun 17, 2019 | A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a lo... |
| CVE-2018-20472 | MEDIUM | 5.4 | 2.1% | Jun 17, 2019 | An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS. |
| CVE-2018-20470 | HIGH | 7.5 | 46.0% | Jun 17, 2019 | An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerab... |
| CVE-2018-20469 | CRITICAL | 9.8 | 18.5% | Jun 17, 2019 | An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to... |
| CVE-2018-20468 | — | — | 2.2% | Jun 17, 2019 | An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" th... |
| CVE-2018-6350 | — | — | 1.7% | Jun 14, 2019 | An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects Wha... |
| CVE-2018-6349 | CRITICAL | 9.8 | 2.2% | Jun 14, 2019 | When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for ... |
| CVE-2018-6339 | — | — | 1.5% | Jun 14, 2019 | When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data bei... |
| CVE-2018-5913 | — | — | 0.2% | Jun 14, 2019 | A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto,... |
| CVE-2018-5911 | — | — | 0.2% | Jun 14, 2019 | Buffer overflow in WLAN function due to improper check of buffer size before copying in Snapdragon Auto, Snapdragon Cons... |
| CVE-2018-5903 | — | — | 0.2% | Jun 14, 2019 | Out of bounds read occurs due to improper validation of array while processing VDEV stop response from WLAN firmware in ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now