2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11544 | CRITICAL | 9.8 | 1.5% | May 29, 2018 | The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are sto... |
| CVE-2018-3745 | CRITICAL | 9.1 | 2.2% | May 29, 2018 | atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below. |
| CVE-2018-3744 | CRITICAL | 9.8 | 2.3% | May 29, 2018 | The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the s... |
| CVE-2018-8871 | CRITICAL | 9.8 | 3.9% | May 25, 2018 | In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based bu... |
| CVE-2018-1000301 | CRITICAL | 9.1 | 6.0% | May 24, 2018 | curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of se... |
| CVE-2018-9019 | CRITICAL | 9.8 | 4.0% | May 22, 2018 | SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2018-4939 | CRITICAL | 9.8 | 63.3% | May 19, 2018 | Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deseria... |
| CVE-2018-4918 | CRITICAL | 9.8 | 12.2% | May 19, 2018 | Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier hav... |
| CVE-2018-4917 | CRITICAL | 9.8 | 17.8% | May 19, 2018 | Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier hav... |
| CVE-2018-10759 | CRITICAL | 9.8 | 1.9% | May 16, 2018 | PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attack... |
| CVE-2018-8845 | CRITICAL | 9.8 | 5.8% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-7499 | CRITICAL | 9.8 | 3.8% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-11091 | CRITICAL | 9.9 | 3.7% | May 14, 2018 | An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. I... |
| CVE-2018-1115 | CRITICAL | 9.1 | 4.0% | May 10, 2018 | postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() func... |
| CVE-2018-10683 | CRITICAL | 9.8 | 1.8% | May 9, 2018 | An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm referenc... |
| CVE-2018-10682 | CRITICAL | 9.8 | 8.2% | May 9, 2018 | An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TC... |
| CVE-2018-10771 | CRITICAL | 9.8 | 3.1% | May 7, 2018 | Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cau... |
| CVE-2018-10753 | CRITICAL | 9.8 | 2.7% | May 5, 2018 | Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers... |
| CVE-2018-8865 | CRITICAL | 9.8 | 5.9% | May 4, 2018 | In Lantech IDS 2102 2.0 and prior, a stack-based buffer overflow vulnerability has been identified which may allow remot... |
| CVE-2018-10562 | CRITICAL | 9.8 | 100.0% | May 4, 2018 | An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac... |
| CVE-2018-10561 | CRITICAL | 9.8 | 93.3% | May 4, 2018 | An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images... |
| CVE-2018-2628 | CRITICAL | 9.8 | 99.4% | Apr 19, 2018 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S... |
| CVE-2018-10191 | CRITICAL | 9.8 | 2.6% | Apr 17, 2018 | In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_G... |
| CVE-2018-0016 | CRITICAL | 9.8 | 4.2% | Apr 11, 2018 | Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS de... |
| CVE-2018-1275 | CRITICAL | 9.8 | 57.6% | Apr 11, 2018 | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow app... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now