2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20122 | — | — | 4.8% | Feb 21, 2019 | The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.... |
| CVE-2018-20146 | — | — | 0.4% | Feb 21, 2019 | An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could... |
| CVE-2018-15380 | HIGH | 8.8 | 1.1% | Feb 20, 2019 | A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent atta... |
| CVE-2018-5819 | — | — | 2.8% | Feb 20, 2019 | An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can b... |
| CVE-2018-5818 | — | — | 2.3% | Feb 20, 2019 | An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be ... |
| CVE-2018-5817 | — | — | 2.5% | Feb 20, 2019 | A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_... |
| CVE-2018-20030 | — | — | 3.8% | Feb 20, 2019 | An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be explo... |
| CVE-2018-20241 | — | — | 0.9% | Feb 20, 2019 | The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to ... |
| CVE-2018-20240 | — | — | 0.9% | Feb 20, 2019 | The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers t... |
| CVE-2018-19106 | — | — | 0.8% | Feb 20, 2019 | Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959. |
| CVE-2018-9867 | MEDIUM | 5.5 | 0.2% | Feb 19, 2019 | In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administra... |
| CVE-2018-20026 | HIGH | 7.5 | 3.0% | Feb 19, 2019 | Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0. |
| CVE-2018-20025 | — | — | 2.6% | Feb 19, 2019 | Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0. |
| CVE-2018-1996 | MEDIUM | 5.3 | 1.1% | Feb 19, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the impro... |
| CVE-2018-3700 | — | — | 0.5% | Feb 18, 2019 | Code injection vulnerability in the installer for Intel(R) USB 3.0 eXtensible Host Controller Driver for Microsoft Windo... |
| CVE-2018-12159 | — | — | 0.3% | Feb 18, 2019 | Buffer overflow in the command-line interface for Intel(R) PROSet Wireless v20.50 and before may allow an authenticated ... |
| CVE-2018-20782 | — | — | 10.0% | Feb 17, 2019 | The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages. |
| CVE-2018-1895 | MEDIUM | 5.4 | 0.7% | Feb 15, 2019 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2018-1727 | HIGH | 7.1 | 2.5% | Feb 15, 2019 | IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attac... |
| CVE-2018-1701 | HIGH | 8.5 | 1.2% | Feb 15, 2019 | IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands ... |
| CVE-2018-6271 | — | — | 0.6% | Feb 13, 2019 | NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software delivers extra data with the buffe... |
| CVE-2018-6268 | — | — | 0.8% | Feb 13, 2019 | NVIDIA Tegra library contains a vulnerability in libnvmmlite_video.so, where referencing memory after it has been freed ... |
| CVE-2018-6267 | — | — | 0.8% | Feb 13, 2019 | NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly v... |
| CVE-2018-19008 | — | — | 1.6% | Feb 13, 2019 | The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser o... |
| CVE-2018-20238 | — | — | 1.5% | Feb 13, 2019 | Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now