2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12918 | CRITICAL | 9.8 | 1.4% | Jun 27, 2018 | In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c. |
| CVE-2018-5435 | CRITICAL | 9.6 | 3.2% | Jun 27, 2018 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analys... |
| CVE-2018-6667 | CRITICAL | 10 | 3.5% | Jun 26, 2018 | Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 a... |
| CVE-2018-1000544 | CRITICAL | 9.8 | 4.5% | Jun 26, 2018 | rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that c... |
| CVE-2018-1000533 | CRITICAL | 9.8 | 75.9% | Jun 26, 2018 | klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in ... |
| CVE-2018-1000517 | CRITICAL | 9.8 | 32.4% | Jun 26, 2018 | BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow... |
| CVE-2018-12714 | CRITICAL | 9.8 | 5.3% | Jun 24, 2018 | An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c cou... |
| CVE-2018-12713 | CRITICAL | 9.1 | 1.9% | Jun 24, 2018 | GIMP through 2.10.2 makes g_get_tmp_dir calls to establish temporary filenames, which may result in a filename that alre... |
| CVE-2018-12640 | CRITICAL | 9.8 | 1.6% | Jun 23, 2018 | The webService binary on Insteon HD IP Camera White 2864-222 devices has a Buffer Overflow via a crafted pid, pwd, or us... |
| CVE-2018-11560 | CRITICAL | 9.8 | 1.6% | Jun 23, 2018 | The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Contro... |
| CVE-2018-12689 | CRITICAL | 9.8 | 1.8% | Jun 22, 2018 | phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a cra... |
| CVE-2018-12634 | CRITICAL | 9.8 | 57.7% | Jun 22, 2018 | CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/lo... |
| CVE-2018-6210 | CRITICAL | 9.8 | 3.1% | Jun 19, 2018 | D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which mak... |
| CVE-2018-9022 | CRITICAL | 9.8 | 20.4% | Jun 18, 2018 | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec... |
| CVE-2018-9021 | CRITICAL | 9.8 | 19.4% | Jun 18, 2018 | An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec... |
| CVE-2018-1085 | CRITICAL | 9 | 2.2% | Jun 15, 2018 | openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificat... |
| CVE-2018-11574 | CRITICAL | 9.8 | 1.9% | Jun 14, 2018 | Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a c... |
| CVE-2018-2424 | CRITICAL | 9.8 | 2.4% | Jun 12, 2018 | SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided Java... |
| CVE-2018-0315 | CRITICAL | 9.8 | 8.1% | Jun 7, 2018 | A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software co... |
| CVE-2018-11743 | CRITICAL | 9.8 | 2.2% | Jun 5, 2018 | The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attack... |
| CVE-2018-11682 | CRITICAL | 9.8 | 4.3% | Jun 2, 2018 | Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a ... |
| CVE-2018-11681 | CRITICAL | 9.8 | 4.3% | Jun 2, 2018 | Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of... |
| CVE-2018-3757 | CRITICAL | 9.8 | 4.6% | Jun 1, 2018 | Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter. |
| CVE-2018-3746 | CRITICAL | 9.8 | 4.9% | Jun 1, 2018 | The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbi... |
| CVE-2018-11138 | CRITICAL | 9.8 | 91.9% | May 31, 2018 | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now