2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3948 | HIGH | 7.5 | 23.1% | Nov 30, 2018 | An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP se... |
| CVE-2018-15768 | — | — | 9.1% | Nov 30, 2018 | Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due... |
| CVE-2018-15767 | — | — | 12.3% | Nov 30, 2018 | The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerab... |
| CVE-2018-1928 | MEDIUM | 6.7 | 0.3% | Nov 30, 2018 | IBM StoredIQ 7.6.0 does not implement proper authorization of user roles due to which it was possible for a low privileg... |
| CVE-2018-1927 | MEDIUM | 6.5 | 0.7% | Nov 30, 2018 | IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau... |
| CVE-2018-1897 | HIGH | 8.4 | 0.6% | Nov 30, 2018 | IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, ... |
| CVE-2018-9072 | — | — | 0.9% | Nov 30, 2018 | In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient i... |
| CVE-2018-16097 | — | — | 0.5% | Nov 30, 2018 | LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated... |
| CVE-2018-16093 | — | — | 0.7% | Nov 30, 2018 | In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient s... |
| CVE-2018-0716 | — | — | 0.8% | Nov 30, 2018 | Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central... |
| CVE-2018-14637 | MEDIUM | 6.1 | 0.8% | Nov 30, 2018 | The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertion... |
| CVE-2018-19777 | — | — | 1.1% | Nov 30, 2018 | In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrate... |
| CVE-2018-19764 | — | — | — | Nov 30, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-19763 | — | — | 0.7% | Nov 30, 2018 | There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a den... |
| CVE-2018-19762 | — | — | 0.8% | Nov 30, 2018 | There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a... |
| CVE-2018-19761 | — | — | 0.7% | Nov 30, 2018 | There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a ... |
| CVE-2018-19760 | — | — | 1.1% | Nov 30, 2018 | cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak. |
| CVE-2018-19759 | — | — | 0.7% | Nov 30, 2018 | There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that wil... |
| CVE-2018-19758 | — | — | 1.7% | Nov 30, 2018 | There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of ser... |
| CVE-2018-19757 | — | — | 0.9% | Nov 30, 2018 | There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that wi... |
| CVE-2018-19756 | — | — | 0.7% | Nov 30, 2018 | There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a den... |
| CVE-2018-19755 | — | — | 1.0% | Nov 30, 2018 | There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will... |
| CVE-2018-19527 | — | — | 0.7% | Nov 29, 2018 | i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings. |
| CVE-2018-19497 | MEDIUM | 6.5 | 1.5% | Nov 29, 2018 | In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is... |
| CVE-2018-1000819 | — | — | — | Nov 29, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-19131. Reason: This candidate is a reservation... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now