2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7788 | MEDIUM | 6.5 | 1.1% | May 22, 2019 | A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40. which co... |
| CVE-2018-12886 | — | — | 2.2% | May 22, 2019 | stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 thro... |
| CVE-2018-7202 | — | — | 0.8% | May 22, 2019 | An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page. |
| CVE-2018-14729 | — | — | 10.6% | May 22, 2019 | The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to ex... |
| CVE-2018-1991 | LOW | 2.7 | 1.0% | May 22, 2019 | IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as... |
| CVE-2018-2005 | LOW | 3.3 | 0.3% | May 20, 2019 | IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive information in process memory that could be read by a local... |
| CVE-2018-12270 | — | — | 0.9% | May 20, 2019 | In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the clie... |
| CVE-2018-16156 | HIGH | 7.8 | 2.6% | May 17, 2019 | In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u... |
| CVE-2018-3701 | — | — | 0.3% | May 17, 2019 | Improper directory permissions in the installer for Intel(R) PROSet/Wireless WiFi Software version 20.100 and earlier ma... |
| CVE-2018-20500 | — | — | 1.4% | May 17, 2019 | An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13... |
| CVE-2018-19585 | — | — | 14.5% | May 17, 2019 | GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection... |
| CVE-2018-17181 | — | — | 1.4% | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/p... |
| CVE-2018-17180 | — | — | 1.9% | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/downloa... |
| CVE-2018-17179 | — | — | 11.9% | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/... |
| CVE-2018-7191 | — | — | 0.7% | May 17, 2019 | In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. Thi... |
| CVE-2018-20839 | MEDIUM | 4.3 | 2.5% | May 17, 2019 | systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstan... |
| CVE-2018-20007 | — | — | 0.5% | May 16, 2019 | Yeelight Smart AI Speaker 3.3.10_0074 devices have improper access control over the UART interface, allowing physical at... |
| CVE-2018-12556 | — | — | 1.8% | May 16, 2019 | The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn relea... |
| CVE-2018-1975 | MEDIUM | 5.4 | 0.7% | May 16, 2019 | IBM Rational DOORS Web Access 9.5.1 through 9.5.2.9, and 9.6 through 9.6.1.9 is vulnerable to cross-site scripting. This... |
| CVE-2018-17048 | — | — | 1.7% | May 16, 2019 | admin/Lib/Action/FpluginAction.class.php in FDCMS (aka Fangfa Content Manage System) 4.2 allows SQL Injection. |
| CVE-2018-14839 | CRITICAL | 9.8 | 89.4% | May 14, 2019 | LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attac... |
| CVE-2018-16656 | — | — | 2.2% | May 14, 2019 | DoBox_CstmBox_Info.model.htm on Kyocera TASKalfa 4002i and 6002i devices allows remote attackers to read the documents o... |
| CVE-2018-8940 | — | — | 1.6% | May 14, 2019 | ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external ... |
| CVE-2018-6885 | — | — | 1.4% | May 14, 2019 | An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.... |
| CVE-2018-11691 | — | — | 2.3% | May 14, 2019 | Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change th... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now