2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12181Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevat...
CVE-2018-12180Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of priv...
CVE-2018-12179Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of ...
CVE-2018-12178Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege an...
CVE-2018-19644MEDIUM5Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM...
CVE-2018-19643MEDIUM4.7Information leakage issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versi...
CVE-2018-19016Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and Compac...
CVE-2018-18994LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file...
CVE-2018-12551When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any mal...
CVE-2018-12550When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or...
CVE-2018-12546MEDIUM6.5In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has it...
CVE-2018-19642MEDIUM5.1Denial of service issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) version...
CVE-2018-19641MEDIUM6.1Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Ma...
CVE-2018-19466A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master passw...
CVE-2018-5927HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.
CVE-2018-5926A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process versio...
CVE-2018-5923In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution a...
CVE-2018-16207PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restricti...
CVE-2018-10934MEDIUM5.4A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA...
CVE-2018-15817FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 v...
CVE-2018-15816FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d7d v...
CVE-2018-15815FastStone Image Viewer 6.5 has an Exception Handler Chain Corrupted issue starting at image00400000+0x00000000003ef68a v...
CVE-2018-15814FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image fil...
CVE-2018-15813FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000000e1237 via a crafted image fil...
CVE-2018-16856MEDIUM5.5In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now