2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17172 | — | — | 2.0% | Jan 3, 2019 | The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 ... |
| CVE-2018-20131 | — | — | 0.3% | Jan 3, 2019 | The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on t... |
| CVE-2018-18893 | — | — | 1.8% | Jan 3, 2019 | Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.jav... |
| CVE-2018-18264 | — | — | 70.4% | Jan 3, 2019 | Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for rea... |
| CVE-2018-20326 | — | — | 4.8% | Jan 2, 2019 | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage... |
| CVE-2018-20211 | — | — | 1.4% | Jan 2, 2019 | ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with ... |
| CVE-2018-20166 | — | — | 7.1% | Jan 2, 2019 | A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a... |
| CVE-2018-20100 | — | — | 0.7% | Jan 2, 2019 | An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect duri... |
| CVE-2018-19478 | — | — | 1.9% | Jan 2, 2019 | In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when ... |
| CVE-2018-19371 | — | — | 6.0% | Jan 2, 2019 | The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive ... |
| CVE-2018-19362 | — | — | 10.6% | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to bl... |
| CVE-2018-19361 | — | — | 10.6% | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to bl... |
| CVE-2018-19360 | — | — | 10.6% | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to bl... |
| CVE-2018-15490 | — | — | 0.6% | Jan 2, 2019 | An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges)... |
| CVE-2018-14721 | — | — | 10.5% | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) a... |
| CVE-2018-14720 | — | — | 7.5% | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by levera... |
| CVE-2018-13045 | — | — | 3.2% | Jan 2, 2019 | SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex... |
| CVE-2018-20659 | — | — | 1.2% | Jan 2, 2019 | An issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in Core/Ap4StcoAtom.cpp has an attempted excessive m... |
| CVE-2018-7900 | — | — | 0.8% | Jan 2, 2019 | There is an information leak vulnerability in some Huawei HG products. An attacker may obtain information about the HG d... |
| CVE-2018-20658 | — | — | 8.5% | Jan 2, 2019 | The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon cr... |
| CVE-2018-5197 | — | — | 1.1% | Jan 2, 2019 | A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow at... |
| CVE-2018-20657 | — | — | 4.0% | Jan 2, 2019 | The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak... |
| CVE-2018-17188 | — | — | 3.2% | Jan 2, 2019 | Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cas... |
| CVE-2018-15803 | — | — | — | Jan 2, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15802 | — | — | — | Jan 2, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now