2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14847 | CRITICAL | 9.1 | 96.1% | Aug 2, 2018 | MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated ... |
| CVE-2018-3881 | CRITICAL | 9.4 | 1.2% | Aug 1, 2018 | An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticate... |
| CVE-2018-12468 | CRITICAL | 9.1 | 2.2% | Aug 1, 2018 | A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attack... |
| CVE-2018-8859 | CRITICAL | 9.8 | 1.6% | Jul 24, 2018 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.... |
| CVE-2018-8855 | CRITICAL | 9.8 | 0.8% | Jul 24, 2018 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.... |
| CVE-2018-8851 | CRITICAL | 9.8 | 1.3% | Jul 24, 2018 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.... |
| CVE-2018-10627 | CRITICAL | 9.8 | 1.2% | Jul 24, 2018 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.... |
| CVE-2018-1999019 | CRITICAL | 9.8 | 3.4% | Jul 23, 2018 | Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint loca... |
| CVE-2018-6678 | CRITICAL | 9.1 | 1.2% | Jul 23, 2018 | Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web Gateway (MWG) MWG 7.8... |
| CVE-2018-6677 | CRITICAL | 9.1 | 2.1% | Jul 23, 2018 | Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows au... |
| CVE-2018-10870 | CRITICAL | 9.8 | 6.2% | Jul 19, 2018 | redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use t... |
| CVE-2018-10620 | CRITICAL | 9.8 | 4.3% | Jul 19, 2018 | AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could ... |
| CVE-2018-7602 | CRITICAL | 9.8 | 99.1% | Jul 19, 2018 | A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows a... |
| CVE-2018-0349 | CRITICAL | 9.8 | 3.0% | Jul 18, 2018 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files ... |
| CVE-2018-2938 | CRITICAL | 9 | 1.9% | Jul 18, 2018 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected a... |
| CVE-2018-14362 | CRITICAL | 9.8 | 3.7% | Jul 17, 2018 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may h... |
| CVE-2018-14361 | CRITICAL | 9.8 | 2.5% | Jul 17, 2018 | An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data. |
| CVE-2018-14360 | CRITICAL | 9.8 | 2.7% | Jul 17, 2018 | An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow becau... |
| CVE-2018-14359 | CRITICAL | 9.8 | 4.1% | Jul 17, 2018 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data... |
| CVE-2018-14358 | CRITICAL | 9.8 | 3.9% | Jul 17, 2018 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer ove... |
| CVE-2018-14357 | CRITICAL | 9.8 | 4.9% | Jul 17, 2018 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute a... |
| CVE-2018-14356 | CRITICAL | 9.8 | 3.2% | Jul 17, 2018 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID. |
| CVE-2018-14354 | CRITICAL | 9.8 | 6.1% | Jul 17, 2018 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute a... |
| CVE-2018-14353 | CRITICAL | 9.8 | 3.7% | Jul 17, 2018 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an int... |
| CVE-2018-14352 | CRITICAL | 9.8 | 4.0% | Jul 17, 2018 | An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not l... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now