7.5
    High

    CVE-2018-5319

    Last Modified: 23 Jan 2018

    RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request.

    Source:Daniele Linguaglossa
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-5315

    Last Modified: 10 Jan 2018

    The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.

    Source:Dennis Veninga
    Published:12 Jan 2018
    7.8
    High

    CVE-2018-5282

    Last Modified: 12 Jan 2018

    Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor disputes this issue because neither a buffer overflow nor a crash can be reproduced; also, reading XML documents is implemented exclusively with managed code within the Microsoft .NET Framework

    Source:Vulnerability-Lab
    Published:8 Jan 2018
    5.4
    Medium

    CVE-2018-5263

    Last Modified: 10 Jan 2018

    The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.

    Source:Mattia Furlani
    Published:8 Jan 2018
    9.8
    Critical

    CVE-2018-5262

    Last Modified: 10 Jan 2018

    A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account.

    Source:Arris Huijgen
    Published:12 Jan 2018
    8
    High

    CVE-2018-5234

    Last Modified: 3 May 2018

    The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in which the goal is execution of arbitrary commands on the host system via vulnerable software.

    Source:embedi
    Published:30 Apr 2018
    9.8
    Critical

    CVE-2018-5211

    Last Modified: 5 Jan 2018

    PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.

    Source:Ahmad Mahfouz
    Published:9 Jan 2018
    7.8
    High

    CVE-2018-5189

    Last Modified: 11 Jan 2018

    Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain system privileges by flipping pool buffer size, aka a "double fetch" vulnerability.

    Source:Fidus InfoSecurity
    Published:11 Jan 2018
    9.8
    Critical

    CVE-2018-5159

    Last Modified: 25 May 2018

    An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

    Source:Google Security Research
    Published:9 May 2018
    8.8
    High

    CVE-2018-5158

    Last Modified: 25 Nov 2025

    The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

    Published:9 May 2018
    8.8
    High

    CVE-2018-5146

    Last Modified: 25 Nov 2025

    An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

    Published:16 Mar 2018
    8.8
    High

    CVE-2018-4937

    Last Modified: 24 Apr 2018

    Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Source:Google Security Research
    Published:10 Apr 2018
    6.5
    Medium

    CVE-2018-4936

    Last Modified: 24 Apr 2018

    Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitation could lead to information disclosure.

    Source:Google Security Research
    Published:10 Apr 2018
    8.8
    High

    CVE-2018-4935

    Last Modified: 24 Apr 2018

    Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Source:Google Security Research
    Published:10 Apr 2018
    6.5
    Medium

    CVE-2018-4934

    Last Modified: 24 Apr 2018

    Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Source:Google Security Research
    Published:10 Apr 2018
    8.8
    High

    CVE-2018-4901

    Last Modified: 21 Nov 2024

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the document identity representation. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

    Published:27 Feb 2018
    9.8
    Critical

    CVE-2018-4879

    Last Modified: 21 Nov 2024

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that processes Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

    Published:27 Feb 2018
    7.8
    High

    CVE-2018-4878

    Last Modified: 3 May 2018

    A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

    Source:SyFi
    Published:1 Feb 2018
    5.5
    Medium

    CVE-2018-4863

    Last Modified: 19 Apr 2018

    Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.

    Source:hyp3rlinx
    Published:5 Apr 2018
    8.8
    High

    CVE-2018-4443

    Last Modified: 2 Jan 2019

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4442

    Last Modified: 16 Jan 2019

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4441

    Last Modified: 11 Mar 2019

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Source:Specter
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4438

    Last Modified: 13 Dec 2018

    A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Source:Google Security Research
    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4435

    Last Modified: 11 Dec 2018

    A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

    Source:Google Security Research
    Published:3 Apr 2019
    5.5
    Medium

    CVE-2018-4431

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4416

    Last Modified: 29 Nov 2018

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.

    Source:Google Security Research
    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4415

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.1.

    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4411

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.

    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4407

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4404

    Last Modified: 14 Dec 2018

    In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.

    Source:Metasploit
    Published:11 Jan 2019
    8.8
    High

    CVE-2018-4386

    Last Modified: 8 Jan 2020

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.

    Source:TJ Corley
    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4384

    Last Modified: 6 Nov 2018

    A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, watchOS 5.1.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4382

    Last Modified: 29 Nov 2018

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1, tvOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.

    Source:Google Security Research
    Published:3 Apr 2019
    9.8
    Critical

    CVE-2018-4367

    Last Modified: 6 Nov 2018

    A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.

    Source:Google Security Research
    Published:3 Apr 2019
    7.5
    High

    CVE-2018-4366

    Last Modified: 6 Nov 2018

    A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.

    Source:Google Security Research
    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4343

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

    Published:3 Apr 2019
    9.8
    Critical

    CVE-2018-4331

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4330

    Last Modified: 21 Nov 2024

    In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.

    Published:11 Jan 2019
    8.8
    High

    CVE-2018-4328

    Last Modified: 25 Sept 2018

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Source:Google Security Research
    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4327

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1.

    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4323

    Last Modified: 25 Sept 2018

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4318

    Last Modified: 25 Sept 2018

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4317

    Last Modified: 25 Sept 2018

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4315

    Last Modified: 25 Sept 2018

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4314

    Last Modified: 25 Sept 2018

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4312

    Last Modified: 25 Sept 2018

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Source:Google Security Research
    Published:3 Apr 2019
    8.8
    High

    CVE-2018-4306

    Last Modified: 25 Sept 2018

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Source:Google Security Research
    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4280

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.

    Published:3 Apr 2019
    7.5
    High

    CVE-2018-4248

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.

    Published:3 Apr 2019
    7.8
    High

    CVE-2018-4243

    Last Modified: 7 Jun 2018

    An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Kernel" component. A buffer overflow in getvolattrlist allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:8 Jun 2018