2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8846 | — | — | 1.3% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutr... |
| CVE-2018-8844 | — | — | 0.9% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently... |
| CVE-2018-8842 | — | — | 0.6% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical... |
| CVE-2018-14803 | — | — | 1.7% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vuln... |
| CVE-2018-15606 | — | — | 0.6% | Sep 26, 2018 | An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an ... |
| CVE-2018-7355 | — | — | 1.9% | Sep 26, 2018 | All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scrip... |
| CVE-2018-7907 | — | — | 0.7% | Sep 26, 2018 | Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, A... |
| CVE-2018-17538 | — | — | 2.5% | Sep 26, 2018 | Axon (formerly TASER International) Evidence Sync 3.15.89 is vulnerable to process injection. NOTE: the vendor's positio... |
| CVE-2018-11763 | — | — | 51.0% | Sep 25, 2018 | In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, s... |
| CVE-2018-6119 | — | — | 0.9% | Sep 25, 2018 | Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents... |
| CVE-2018-6055 | — | — | 1.1% | Sep 25, 2018 | Insufficient policy enforcement in Catalog Service in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to ... |
| CVE-2018-6054 | — | — | 1.4% | Sep 25, 2018 | Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap co... |
| CVE-2018-6053 | — | — | 0.8% | Sep 25, 2018 | Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view we... |
| CVE-2018-6052 | — | — | 1.3% | Sep 25, 2018 | Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a r... |
| CVE-2018-6051 | — | — | 1.3% | Sep 25, 2018 | XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page... |
| CVE-2018-6050 | — | — | 1.3% | Sep 25, 2018 | Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents... |
| CVE-2018-6049 | — | — | 1.5% | Sep 25, 2018 | Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof t... |
| CVE-2018-6048 | — | — | 1.3% | Sep 25, 2018 | Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentiall... |
| CVE-2018-6047 | — | — | 1.4% | Sep 25, 2018 | Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentiall... |
| CVE-2018-6046 | — | — | 1.2% | Sep 25, 2018 | Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentiall... |
| CVE-2018-6045 | — | — | 1.5% | Sep 25, 2018 | Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potenti... |
| CVE-2018-6043 | — | — | 1.7% | Sep 25, 2018 | Insufficient data validation in External Protocol Handler in Google Chrome prior to 64.0.3282.119 allowed a remote attac... |
| CVE-2018-6042 | — | — | 1.2% | Sep 25, 2018 | Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents... |
| CVE-2018-6041 | — | — | 1.3% | Sep 25, 2018 | Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the conte... |
| CVE-2018-6040 | — | — | 1.4% | Sep 25, 2018 | Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentiall... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now