2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20193 | — | — | 1.3% | Dec 21, 2018 | Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by... |
| CVE-2018-19323 | CRITICAL | 9.8 | 8.5% | Dec 21, 2018 | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ... |
| CVE-2018-19322 | HIGH | 7.8 | 1.9% | Dec 21, 2018 | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X... |
| CVE-2018-19321 | HIGH | 7.8 | 3.7% | Dec 21, 2018 | The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X... |
| CVE-2018-19320 | HIGH | 7.8 | 3.6% | Dec 21, 2018 | The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ... |
| CVE-2018-18009 | CRITICAL | 9.8 | 2.7% | Dec 21, 2018 | dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials. |
| CVE-2018-18008 | — | — | 2.0% | Dec 21, 2018 | spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credenti... |
| CVE-2018-18007 | CRITICAL | 9.8 | 1.9% | Dec 21, 2018 | atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials. |
| CVE-2018-16778 | — | — | 0.8% | Dec 21, 2018 | Cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0 allows remote attackers to inject arbitrary we... |
| CVE-2018-20346 | — | — | 9.7% | Dec 21, 2018 | SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow)... |
| CVE-2018-20345 | — | — | 0.7% | Dec 21, 2018 | Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attack... |
| CVE-2018-20342 | — | — | 0.6% | Dec 21, 2018 | The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This all... |
| CVE-2018-5202 | — | — | 1.5% | Dec 21, 2018 | SKCertService 2.5.5 and earlier contains a vulnerability that could allow remote attacker to execute arbitrary code. Thi... |
| CVE-2018-5201 | — | — | 0.7% | Dec 21, 2018 | Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and... |
| CVE-2018-5196 | HIGH | 8.8 | 1.4% | Dec 21, 2018 | Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim... |
| CVE-2018-18332 | — | — | 1.4% | Dec 21, 2018 | A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissi... |
| CVE-2018-18331 | — | — | 1.4% | Dec 21, 2018 | A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow ... |
| CVE-2018-18330 | — | — | 1.0% | Dec 21, 2018 | An Address Bar Spoofing vulnerability in Trend Micro Dr. Safety for Android (Consumer) versions 3.0.1324 and below could... |
| CVE-2018-11794 | — | — | — | Dec 21, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-20339 | — | — | 2.4% | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. |
| CVE-2018-20338 | — | — | 11.5% | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. |
| CVE-2018-20337 | — | — | 2.1% | Dec 21, 2018 | There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted inp... |
| CVE-2018-20332 | — | — | 2.2% | Dec 21, 2018 | An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files... |
| CVE-2018-20330 | — | — | 2.0% | Dec 21, 2018 | The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via ... |
| CVE-2018-20329 | — | — | 1.2% | Dec 21, 2018 | Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users wit... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now