2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13382 | HIGH | 7.5 | 81.7% | Jun 4, 2019 | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti... |
| CVE-2018-13381 | HIGH | 7.5 | 1.8% | Jun 4, 2019 | A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions a... |
| CVE-2018-13380 | MEDIUM | 6.1 | 62.5% | Jun 4, 2019 | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and ... |
| CVE-2018-13379 | CRITICAL | 9.8 | 100.0% | Jun 4, 2019 | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.... |
| CVE-2018-5406 | HIGH | 8.8 | 12.2% | Jun 3, 2019 | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-O... |
| CVE-2018-5405 | — | — | 3.7% | Jun 3, 2019 | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated least privileged user with 'User Cons... |
| CVE-2018-5404 | — | — | 3.8% | Jun 3, 2019 | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privilege... |
| CVE-2018-20815 | — | — | 4.4% | May 31, 2019 | In QEMU 3.1.0, load_device_tree in device_tree.c calls the deprecated load_image function, which has a buffer overflow r... |
| CVE-2018-14425 | — | — | 1.0% | May 30, 2019 | There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra We... |
| CVE-2018-10948 | — | — | 0.8% | May 30, 2019 | Synacor Zimbra Admin UI in Zimbra Collaboration Suite before 8.8.0 beta 2 has Persistent XSS via mail addrs. |
| CVE-2018-9193 | HIGH | 7.8 | 0.4% | May 30, 2019 | A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.... |
| CVE-2018-9191 | — | — | 0.3% | May 30, 2019 | A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthori... |
| CVE-2018-4048 | HIGH | 7.8 | 0.6% | May 30, 2019 | An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in ... |
| CVE-2018-13368 | — | — | 0.8% | May 30, 2019 | A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attacker to execute unauthoriz... |
| CVE-2018-8029 | — | — | 4.0% | May 30, 2019 | In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn use... |
| CVE-2018-20840 | — | — | 0.7% | May 30, 2019 | An unhandled exception vulnerability exists during Google Sign-In with Google API C++ Client before 2019-04-10. It poten... |
| CVE-2018-15131 | — | — | 1.9% | May 30, 2019 | An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, ... |
| CVE-2018-12130 | MEDIUM | 5.9 | 1.6% | May 30, 2019 | Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative executi... |
| CVE-2018-12127 | MEDIUM | 5.6 | 1.5% | May 30, 2019 | Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution m... |
| CVE-2018-12126 | MEDIUM | 5.6 | 1.5% | May 30, 2019 | Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execu... |
| CVE-2018-20160 | — | — | 2.2% | May 29, 2019 | ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and... |
| CVE-2018-18631 | — | — | 1.0% | May 29, 2019 | mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 h... |
| CVE-2018-14013 | — | — | 7.4% | May 29, 2019 | Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. |
| CVE-2018-13365 | — | — | 0.9% | May 29, 2019 | An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as... |
| CVE-2018-19978 | — | — | 4.1% | May 29, 2019 | A buffer overflow vulnerability in the DHCP and PPPOE configuration interface of the Auerswald COMfort 1200 IP phone 3.4... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now