2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19976 | — | — | 1.3% | Dec 17, 2018 | In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara... |
| CVE-2018-19975 | — | — | 1.4% | Dec 17, 2018 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in liby... |
| CVE-2018-19974 | — | — | 1.3% | Dec 17, 2018 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libya... |
| CVE-2018-19936 | — | — | 1.1% | Dec 17, 2018 | PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion. |
| CVE-2018-19933 | — | — | 3.5% | Dec 17, 2018 | Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and Ne... |
| CVE-2018-19828 | — | — | 2.3% | Dec 17, 2018 | Artica Integria IMS 5.0.83 has XSS via the search_string parameter. |
| CVE-2018-19036 | — | — | 2.4% | Dec 17, 2018 | An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could pote... |
| CVE-2018-18556 | CRITICAL | 9.9 | 15.4% | Dec 17, 2018 | A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu... |
| CVE-2018-18555 | — | — | 1.8% | Dec 17, 2018 | A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to adm... |
| CVE-2018-16596 | — | — | 0.7% | Dec 17, 2018 | A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, an... |
| CVE-2018-14856 | — | — | 0.9% | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-... |
| CVE-2018-14855 | — | — | 0.9% | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-F... |
| CVE-2018-14854 | — | — | 0.9% | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-... |
| CVE-2018-14853 | — | — | 0.9% | Dec 17, 2018 | A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4... |
| CVE-2018-14852 | — | — | 1.0% | Dec 17, 2018 | Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver... |
| CVE-2018-1891 | MEDIUM | 5.4 | 1.0% | Dec 17, 2018 | IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2018-1889 | MEDIUM | 5.4 | 1.0% | Dec 17, 2018 | IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2018-20172 | — | — | 1.6% | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbo... |
| CVE-2018-20171 | — | — | 1.6% | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php ... |
| CVE-2018-20027 | — | — | 1.8% | Dec 17, 2018 | The yaml_parse.load method in Pylearn2 allows code injection. |
| CVE-2018-19822 | — | — | 1.1% | Dec 17, 2018 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/SharedC... |
| CVE-2018-19821 | — | — | 1.1% | Dec 17, 2018 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Securit... |
| CVE-2018-19820 | — | — | 1.1% | Dec 17, 2018 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Roles.j... |
| CVE-2018-19819 | — | — | 1.1% | Dec 17, 2018 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Rights.... |
| CVE-2018-19818 | — | — | 1.1% | Dec 17, 2018 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Contact... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now