Skip to main content

Year archive

CVEs published in 2018

Archive summary

16,510 CVEs published in 2018 — 2,545 Critical, 7,428 High, 6,299 Medium, 238 Low, 0 Unrated.

CVE-2018-1000815

Published Dec 20, 2018

Brave Software Inc. Brave version version 0.22.810 to 0.24.0 contains a Other/Unknown vulnerability in function ContentSettingsObserver::AllowScript() in content_settings_observer…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000814

Published Dec 20, 2018

aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000813

Published Dec 20, 2018

Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Ex…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000812

Published Dec 20, 2018

Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password reco…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000811

Published Dec 20, 2018

bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9704

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, There is no synchronization between msm_vb2 buffer operations which can…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7365

Published Dec 20, 2018

All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerability, which may allow an unauthorized user to perform unautho…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5200

Published Dec 20, 2018

KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5199

Published Dec 20, 2018

In Veraport G3 ALL on MacOS, due to insufficient domain validation, It is possible to overwrite installation file to malicious file. A remote unauthenticated attacker may use this…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5198

Published Dec 20, 2018

In Veraport G3 ALL on MacOS, a race condition when calling the Veraport API allow remote attacker to cause arbitrary file download and execution. This results in remote code execu…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1973

Published Dec 20, 2018

IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functio…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1784

Published Dec 20, 2018

IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1778

Published Dec 20, 2018

IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is t…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1771

Published Dec 20, 2018

IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1677

Published Dec 20, 2018

IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system. A…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1661

Published Dec 20, 2018

IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitt…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8653

Published Dec 20, 2018

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerabi…

CVSS 7.5 · High
evidence mentions
5
Buzz score
49.4
KEV listed

CVE-2018-6669

Published Dec 20, 2018

A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20307

Published Dec 20, 2018

Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging inc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20306

Published Dec 20, 2018

A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inj…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20301

Published Dec 20, 2018

An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20304

Published Dec 20, 2018

wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long second argument. NOTE: this is not a Microsoft prod…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20303

Published Dec 20, 2018

In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20302

Published Dec 20, 2018

An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 16,510 CVEsPage 19 of 661