2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19873 | CRITICAL | 9.8 | 3.4% | Dec 26, 2018 | An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data. |
| CVE-2018-11742 | CRITICAL | 9.8 | 14.3% | Dec 26, 2018 | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI. |
| CVE-2018-11741 | CRITICAL | 9.8 | 17.9% | Dec 26, 2018 | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure vi... |
| CVE-2018-20445 | CRITICAL | 9.8 | 1.9% | Dec 25, 2018 | D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover Wi... |
| CVE-2018-20396 | CRITICAL | 9.8 | 1.5% | Dec 23, 2018 | NET&SYS MNG2120J 5.76.1006c and MNG6300 5.83.6305jrc2 devices allow remote attackers to discover credentials via iso.3.6... |
| CVE-2018-20386 | CRITICAL | 9.8 | 1.8% | Dec 23, 2018 | ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4... |
| CVE-2018-20383 | CRITICAL | 9.8 | 1.8% | Dec 23, 2018 | ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.... |
| CVE-2018-19323 | CRITICAL | 9.8 | 8.5% | Dec 21, 2018 | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ... |
| CVE-2018-18009 | CRITICAL | 9.8 | 2.7% | Dec 21, 2018 | dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials. |
| CVE-2018-18007 | CRITICAL | 9.8 | 1.9% | Dec 21, 2018 | atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials. |
| CVE-2018-1160 | CRITICAL | 9.8 | 86.5% | Dec 20, 2018 | Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking... |
| CVE-2018-1000875 | CRITICAL | 9.8 | 1.7% | Dec 20, 2018 | Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: A... |
| CVE-2018-1000837 | CRITICAL | 10 | 1.8% | Dec 20, 2018 | UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can resu... |
| CVE-2018-1000835 | CRITICAL | 10 | 1.8% | Dec 20, 2018 | KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can resul... |
| CVE-2018-1000828 | CRITICAL | 9 | 1.3% | Dec 20, 2018 | FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the ... |
| CVE-2018-1000823 | CRITICAL | 10 | 1.9% | Dec 20, 2018 | exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can res... |
| CVE-2018-20299 | CRITICAL | 9.8 | 1.9% | Dec 19, 2018 | An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firm... |
| CVE-2018-20019 | CRITICAL | 9.8 | 9.4% | Dec 19, 2018 | LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities ... |
| CVE-2018-17777 | CRITICAL | 9.8 | 1.9% | Dec 18, 2018 | An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the defaul... |
| CVE-2018-18556 | CRITICAL | 9.9 | 15.4% | Dec 17, 2018 | A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu... |
| CVE-2018-6703 | CRITICAL | 9.8 | 3.2% | Dec 11, 2018 | Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows re... |
| CVE-2018-20062 | CRITICAL | 9.8 | 99.5% | Dec 11, 2018 | An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP... |
| CVE-2018-1000861 | CRITICAL | 9.8 | 98.3% | Dec 10, 2018 | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea... |
| CVE-2018-9578 | CRITICAL | 9.8 | 0.8% | Dec 7, 2018 | In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bo... |
| CVE-2018-7364 | CRITICAL | 9.8 | 10.3% | Dec 7, 2018 | All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now