2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9556 | CRITICAL | 9.8 | 2.0% | Dec 6, 2018 | In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This c... |
| CVE-2018-16792 | CRITICAL | 9.1 | 1.4% | Dec 5, 2018 | SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file ... |
| CVE-2018-1002105 | CRITICAL | 9.8 | 87.0% | Dec 5, 2018 | In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg... |
| CVE-2018-8787 | CRITICAL | 9.8 | 8.4% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function g... |
| CVE-2018-8786 | CRITICAL | 9.8 | 8.2% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function... |
| CVE-2018-8785 | CRITICAL | 9.8 | 7.3% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a... |
| CVE-2018-8784 | CRITICAL | 9.8 | 7.3% | Nov 29, 2018 | FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that resu... |
| CVE-2018-17930 | CRITICAL | 9.8 | 7.3% | Nov 28, 2018 | A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, wh... |
| CVE-2018-15441 | CRITICAL | 9.4 | 3.7% | Nov 28, 2018 | A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote at... |
| CVE-2018-19410 | CRITICAL | 9.8 | 85.7% | Nov 21, 2018 | PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privile... |
| CVE-2018-18439 | CRITICAL | 9.8 | 2.0% | Nov 20, 2018 | DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traf... |
| CVE-2018-15761 | CRITICAL | 9.9 | 1.7% | Nov 19, 2018 | Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which... |
| CVE-2018-15759 | CRITICAL | 9.1 | 1.7% | Nov 19, 2018 | Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials... |
| CVE-2018-19355 | CRITICAL | 9.8 | 3.5% | Nov 19, 2018 | modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows... |
| CVE-2018-18805 | CRITICAL | 9.8 | 5.2% | Nov 16, 2018 | Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. |
| CVE-2018-18761 | CRITICAL | 9.8 | 16.5% | Nov 16, 2018 | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. |
| CVE-2018-18755 | CRITICAL | 9.8 | 3.1% | Nov 16, 2018 | K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up... |
| CVE-2018-7360 | CRITICAL | 9.6 | 1.0% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may a... |
| CVE-2018-7359 | CRITICAL | 9 | 1.9% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which... |
| CVE-2018-16850 | CRITICAL | 9.8 | 5.1% | Nov 13, 2018 | postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER .... |
| CVE-2018-15439 | CRITICAL | 9.8 | 49.7% | Nov 8, 2018 | A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass ... |
| CVE-2018-15394 | CRITICAL | 9.8 | 4.0% | Nov 8, 2018 | A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthentic... |
| CVE-2018-15381 | CRITICAL | 9.8 | 87.3% | Nov 8, 2018 | A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to exe... |
| CVE-2018-18590 | CRITICAL | 9.6 | 1.0% | Nov 7, 2018 | A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge conta... |
| CVE-2018-14667 | CRITICAL | 9.8 | 74.2% | Nov 6, 2018 | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now