2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18814 | HIGH | 8.8 | 3.1% | Jan 16, 2019 | The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketpla... |
| CVE-2018-18813 | HIGH | 8.8 | 1.5% | Jan 16, 2019 | The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TI... |
| CVE-2018-18812 | MEDIUM | 6.5 | 1.2% | Jan 16, 2019 | The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO... |
| CVE-2018-5741 | MEDIUM | 6.5 | 3.5% | Jan 16, 2019 | To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides... |
| CVE-2018-5740 | HIGH | 7.5 | 59.4% | Jan 16, 2019 | "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS... |
| CVE-2018-5739 | MEDIUM | 6.5 | 1.9% | Jan 16, 2019 | An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certa... |
| CVE-2018-5738 | MEDIUM | 5.3 | 11.1% | Jan 16, 2019 | Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, ... |
| CVE-2018-5737 | MEDIUM | 5.9 | 10.4% | Jan 16, 2019 | A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.... |
| CVE-2018-5736 | — | — | 17.9% | Jan 16, 2019 | An error in zone database reference counting can lead to an assertion failure if a server which is running an affected v... |
| CVE-2018-5734 | HIGH | 7.5 | 6.2% | Jan 16, 2019 | While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcod... |
| CVE-2018-5733 | HIGH | 7.5 | 20.2% | Jan 16, 2019 | A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eve... |
| CVE-2018-15782 | HIGH | 7.7 | 0.4% | Jan 16, 2019 | The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal... |
| CVE-2018-3311 | — | — | 1.7% | Jan 16, 2019 | Vulnerability in the Oracle Retail Xstore Payment component of Oracle Retail Applications (subcomponent: Security). The ... |
| CVE-2018-3309 | — | — | 0.5% | Jan 16, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version... |
| CVE-2018-3305 | — | — | 1.0% | Jan 16, 2019 | Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen... |
| CVE-2018-3304 | — | — | 1.5% | Jan 16, 2019 | Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen... |
| CVE-2018-3303 | — | — | 1.2% | Jan 16, 2019 | Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponen... |
| CVE-2018-3125 | — | — | 1.2% | Jan 16, 2019 | Vulnerability in the Oracle Retail Merchandising System component of Oracle Retail Applications (subcomponent: Security ... |
| CVE-2018-20726 | — | — | 1.0% | Jan 16, 2019 | A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escapi... |
| CVE-2018-20725 | — | — | 1.0% | Jan 16, 2019 | A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping o... |
| CVE-2018-20724 | — | — | 1.0% | Jan 16, 2019 | A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of uninte... |
| CVE-2018-20723 | — | — | 1.0% | Jan 16, 2019 | A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping o... |
| CVE-2018-20721 | CRITICAL | 9.8 | 2.1% | Jan 16, 2019 | URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomple... |
| CVE-2018-20720 | — | — | 2.5% | Jan 16, 2019 | ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause... |
| CVE-2018-7603 | — | — | 0.8% | Jan 15, 2019 | In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerabilit... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now