2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3872 | CRITICAL | 9.9 | 1.8% | Aug 23, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-3866 | CRITICAL | 9.9 | 1.5% | Aug 23, 2018 | An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsun... |
| CVE-2018-3856 | CRITICAL | 9.9 | 3.4% | Aug 23, 2018 | An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 -... |
| CVE-2018-3919 | CRITICAL | 9.9 | 0.9% | Aug 23, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in video-core's HTTP... |
| CVE-2018-3917 | CRITICAL | 9.9 | 0.9% | Aug 23, 2018 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts... |
| CVE-2018-3905 | CRITICAL | 9.9 | 1.5% | Aug 23, 2018 | An exploitable buffer overflow vulnerability exists in the camera "create" feature of video-core's HTTP server of Samsun... |
| CVE-2018-3903 | CRITICAL | 9.9 | 1.8% | Aug 23, 2018 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extract... |
| CVE-2018-3902 | CRITICAL | 9.9 | 1.8% | Aug 23, 2018 | An exploitable buffer overflow vulnerability exists in the camera "replace" feature of video-core's HTTP server of Samsu... |
| CVE-2018-3878 | CRITICAL | 9.9 | 1.5% | Aug 23, 2018 | Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Sam... |
| CVE-2018-3867 | CRITICAL | 9.9 | 2.0% | Aug 23, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-co... |
| CVE-2018-3863 | CRITICAL | 9.9 | 1.7% | Aug 23, 2018 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extract... |
| CVE-2018-3832 | CRITICAL | 9 | 1.7% | Aug 23, 2018 | An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows... |
| CVE-2018-6692 | CRITICAL | 10 | 3.7% | Aug 21, 2018 | Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers t... |
| CVE-2018-1000639 | CRITICAL | 9.6 | 1.6% | Aug 20, 2018 | LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result ... |
| CVE-2018-3785 | CRITICAL | 9.8 | 4.0% | Aug 17, 2018 | A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter. |
| CVE-2018-3784 | CRITICAL | 9.8 | 3.3% | Aug 17, 2018 | A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserial... |
| CVE-2018-10511 | CRITICAL | 10 | 2.7% | Aug 15, 2018 | A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side r... |
| CVE-2018-8273 | CRITICAL | 9.8 | 29.2% | Aug 15, 2018 | A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected... |
| CVE-2018-15152 | CRITICAL | 9.1 | 25.9% | Aug 15, 2018 | Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote... |
| CVE-2018-3938 | CRITICAL | 9.1 | 3.3% | Aug 14, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPEL... |
| CVE-2018-3937 | CRITICAL | 9.1 | 9.6% | Aug 14, 2018 | An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series... |
| CVE-2018-10931 | CRITICAL | 9.8 | 67.9% | Aug 9, 2018 | It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unaut... |
| CVE-2018-14933 | CRITICAL | 9.8 | 93.7% | Aug 4, 2018 | upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par... |
| CVE-2018-9866 | CRITICAL | 9.8 | 4.5% | Aug 3, 2018 | A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management S... |
| CVE-2018-3777 | CRITICAL | 9.8 | 1.5% | Aug 3, 2018 | Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API r... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now