2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18565 | — | — | 0.5% | Nov 20, 2018 | An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x bef... |
| CVE-2018-18564 | — | — | 0.6% | Nov 20, 2018 | An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x bef... |
| CVE-2018-18563 | — | — | 1.0% | Nov 20, 2018 | An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x bef... |
| CVE-2018-18562 | — | — | 0.7% | Nov 20, 2018 | An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h23... |
| CVE-2018-18561 | — | — | 0.7% | Nov 20, 2018 | An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h23... |
| CVE-2018-18440 | — | — | 0.6% | Nov 20, 2018 | DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem ... |
| CVE-2018-16224 | — | — | 6.6% | Nov 20, 2018 | Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to ret... |
| CVE-2018-16223 | — | — | 2.1% | Nov 20, 2018 | Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application th... |
| CVE-2018-16222 | — | — | 0.5% | Nov 20, 2018 | Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.... |
| CVE-2018-12038 | — | — | 0.6% | Nov 20, 2018 | An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key... |
| CVE-2018-12037 | — | — | 0.2% | Nov 20, 2018 | An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA... |
| CVE-2018-17948 | — | — | 0.6% | Nov 20, 2018 | An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3. |
| CVE-2018-19367 | — | — | 1.5% | Nov 20, 2018 | Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already crea... |
| CVE-2018-19335 | — | — | 0.4% | Nov 20, 2018 | Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b... |
| CVE-2018-19334 | — | — | 0.3% | Nov 20, 2018 | Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b... |
| CVE-2018-10099 | — | — | 0.3% | Nov 20, 2018 | Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b... |
| CVE-2018-9209 | — | — | 1.8% | Nov 19, 2018 | Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2 |
| CVE-2018-9207 | — | — | 3.5% | Nov 19, 2018 | Arbitrary file upload in jQuery Upload File <= 4.0.2 |
| CVE-2018-17190 | — | — | 8.7% | Nov 19, 2018 | In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then r... |
| CVE-2018-18519 | — | — | 0.8% | Nov 19, 2018 | BestXsoftware Best Free Keylogger before 6.0.0 allows local users to gain privileges via a Trojan horse "%PROGRAMFILES%\... |
| CVE-2018-19358 | — | — | 0.5% | Nov 18, 2018 | GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bu... |
| CVE-2018-19353 | — | — | 1.1% | Nov 18, 2018 | The ansilove_ansi function in loaders/ansi.c in libansilove 1.0.0 allows remote attackers to cause a denial of service (... |
| CVE-2018-19352 | — | — | 1.3% | Nov 18, 2018 | Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js ha... |
| CVE-2018-19351 | — | — | 1.5% | Nov 18, 2018 | Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have th... |
| CVE-2018-19350 | — | — | 0.5% | Nov 17, 2018 | In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, a... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now