2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3873 | CRITICAL | 9.9 | 1.8% | Sep 21, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-14643 | CRITICAL | 9.8 | 6.0% | Sep 21, 2018 | An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can u... |
| CVE-2018-17254 | CRITICAL | 9.8 | 83.0% | Sep 20, 2018 | The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. |
| CVE-2018-17232 | CRITICAL | 9.8 | 1.7% | Sep 20, 2018 | SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 ... |
| CVE-2018-17207 | CRITICAL | 9.8 | 57.6% | Sep 19, 2018 | An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and... |
| CVE-2018-1000802 | CRITICAL | 9.8 | 20.8% | Sep 18, 2018 | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements u... |
| CVE-2018-11058 | CRITICAL | 9.8 | 4.0% | Sep 14, 2018 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C... |
| CVE-2018-17036 | CRITICAL | 9.8 | 1.7% | Sep 14, 2018 | An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain par... |
| CVE-2018-16836 | CRITICAL | 9.8 | 61.4% | Sep 11, 2018 | Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attac... |
| CVE-2018-3875 | CRITICAL | 9.9 | 1.5% | Sep 10, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-16763 | CRITICAL | 9.8 | 82.9% | Sep 9, 2018 | FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca... |
| CVE-2018-1567 | CRITICAL | 9.8 | 4.2% | Sep 7, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code thro... |
| CVE-2018-16402 | CRITICAL | 9.8 | 3.7% | Sep 3, 2018 | libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application cra... |
| CVE-2018-7791 | CRITICAL | 9.8 | 1.9% | Aug 29, 2018 | A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all ref... |
| CVE-2018-7790 | CRITICAL | 9.8 | 2.5% | Aug 29, 2018 | An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all v... |
| CVE-2018-15873 | CRITICAL | 9.8 | 1.1% | Aug 28, 2018 | A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter. |
| CVE-2018-15839 | CRITICAL | 9.8 | 45.3% | Aug 28, 2018 | D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. |
| CVE-2018-3904 | CRITICAL | 9.9 | 1.8% | Aug 27, 2018 | An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsun... |
| CVE-2018-11653 | CRITICAL | 9.8 | 2.1% | Aug 24, 2018 | Information disclosure in Netwave IP camera at //etc/RT2870STA.dat (via HTTP on port 8000) allows an unauthenticated att... |
| CVE-2018-3786 | CRITICAL | 9.8 | 12.3% | Aug 24, 2018 | A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously ... |
| CVE-2018-14599 | CRITICAL | 9.8 | 5.0% | Aug 24, 2018 | An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-on... |
| CVE-2018-11061 | CRITICAL | 9.1 | 5.0% | Aug 24, 2018 | RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to... |
| CVE-2018-1722 | CRITICAL | 10 | 9.0% | Aug 24, 2018 | IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control... |
| CVE-2018-3907 | CRITICAL | 10 | 1.4% | Aug 24, 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET... |
| CVE-2018-3880 | CRITICAL | 9.9 | 1.2% | Aug 23, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of vide... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now