2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19003 | — | — | 2.6% | Dec 14, 2018 | GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C... |
| CVE-2018-18984 | MEDIUM | 4.6 | 0.3% | Dec 14, 2018 | Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI informa... |
| CVE-2018-18006 | — | — | 21.5% | Dec 14, 2018 | Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any exte... |
| CVE-2018-16875 | MEDIUM | 5.9 | 6.3% | Dec 14, 2018 | The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for eac... |
| CVE-2018-16874 | HIGH | 8.1 | 5.0% | Dec 14, 2018 | In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed wi... |
| CVE-2018-16873 | HIGH | 8.1 | 66.3% | Dec 14, 2018 | In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed ... |
| CVE-2018-6707 | LOW | 3.7 | 0.3% | Dec 14, 2018 | Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5... |
| CVE-2018-3705 | — | — | 0.3% | Dec 14, 2018 | Improper directory permissions in the installer for the Intel(R) System Defense Utility (all versions) may allow authent... |
| CVE-2018-3704 | — | — | 0.3% | Dec 14, 2018 | Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated u... |
| CVE-2018-18097 | — | — | 0.3% | Dec 14, 2018 | Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potent... |
| CVE-2018-18096 | — | — | 0.3% | Dec 14, 2018 | Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to pot... |
| CVE-2018-18093 | — | — | 0.3% | Dec 14, 2018 | Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged use... |
| CVE-2018-14623 | MEDIUM | 4.3 | 1.4% | Dec 14, 2018 | A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to... |
| CVE-2018-12206 | — | — | 0.3% | Dec 14, 2018 | Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenti... |
| CVE-2018-5411 | — | — | 0.8% | Dec 13, 2018 | Pixar's Tractor software, versions 2.2 and earlier, contain a stored cross-site scripting vulnerability in the field tha... |
| CVE-2018-15776 | MEDIUM | 6.4 | 0.4% | Dec 13, 2018 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated... |
| CVE-2018-15774 | LOW | 3.8 | 0.9% | Dec 13, 2018 | Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and... |
| CVE-2018-15754 | MEDIUM | 4.2 | 1.8% | Dec 13, 2018 | Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identi... |
| CVE-2018-16872 | MEDIUM | 5.3 | 1.1% | Dec 13, 2018 | A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_par... |
| CVE-2018-20145 | — | — | 1.6% | Dec 13, 2018 | Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the def... |
| CVE-2018-19489 | MEDIUM | 4.7 | 0.4% | Dec 13, 2018 | v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race conditio... |
| CVE-2018-19439 | — | — | 20.5% | Dec 13, 2018 | XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later vers... |
| CVE-2018-19364 | MEDIUM | 5.5 | 0.5% | Dec 13, 2018 | hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading ... |
| CVE-2018-19118 | — | — | 6.7% | Dec 13, 2018 | Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer... |
| CVE-2018-19039 | — | — | 7.3% | Dec 13, 2018 | Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now