2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000628 | — | — | 2.8% | Dec 28, 2018 | Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the direct checking of t... |
| CVE-2018-1000627 | — | — | 2.3% | Dec 28, 2018 | Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict ... |
| CVE-2018-1000626 | — | — | 2.8% | Dec 28, 2018 | Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the lack of requirement ... |
| CVE-2018-1000625 | — | — | 2.3% | Dec 28, 2018 | Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vu... |
| CVE-2018-1000624 | — | — | 2.2% | Dec 28, 2018 | Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive fun... |
| CVE-2018-15335 | — | — | 1.4% | Dec 28, 2018 | When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth au... |
| CVE-2018-15334 | — | — | 0.7% | Dec 28, 2018 | A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM... |
| CVE-2018-15333 | — | — | 0.4% | Dec 28, 2018 | On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including ... |
| CVE-2018-20524 | — | — | 0.7% | Dec 27, 2018 | The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV... |
| CVE-2018-20520 | — | — | 0.9% | Dec 27, 2018 | MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233. |
| CVE-2018-20519 | — | — | 1.0% | Dec 27, 2018 | An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by c... |
| CVE-2018-20511 | — | — | 0.4% | Dec 27, 2018 | An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c al... |
| CVE-2018-20508 | — | — | 1.5% | Dec 27, 2018 | CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, a... |
| CVE-2018-20502 | — | — | 1.1% | Dec 26, 2018 | An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer cl... |
| CVE-2018-20404 | — | — | 1.5% | Dec 26, 2018 | ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack v... |
| CVE-2018-19871 | — | — | 1.9% | Dec 26, 2018 | An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption. |
| CVE-2018-19870 | — | — | 2.4% | Dec 26, 2018 | An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resu... |
| CVE-2018-19869 | — | — | 2.2% | Dec 26, 2018 | An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp. |
| CVE-2018-19799 | — | — | 4.5% | Dec 26, 2018 | Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. |
| CVE-2018-19616 | — | — | 30.3% | Dec 26, 2018 | An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/rem... |
| CVE-2018-19182 | — | — | 0.6% | Dec 26, 2018 | Engelsystem before commit hash 2e28336 allows CSRF. |
| CVE-2018-18537 | — | — | 0.5% | Dec 26, 2018 | The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbi... |
| CVE-2018-18536 | — | — | 0.6% | Dec 26, 2018 | The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data ... |
| CVE-2018-18535 | — | — | 0.6% | Dec 26, 2018 | The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Spec... |
| CVE-2018-17987 | — | — | 0.9% | Dec 26, 2018 | The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain b... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now