2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11002 | — | — | 0.9% | Nov 29, 2018 | Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions. |
| CVE-2018-18649 | — | — | 6.7% | Nov 29, 2018 | An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, ... |
| CVE-2018-12245 | — | — | 1.1% | Nov 29, 2018 | Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case ... |
| CVE-2018-12239 | — | — | 0.5% | Nov 29, 2018 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection S... |
| CVE-2018-12238 | — | — | 0.4% | Nov 29, 2018 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection S... |
| CVE-2018-19666 | — | — | 0.8% | Nov 29, 2018 | The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversa... |
| CVE-2018-19664 | — | — | 1.7% | Nov 29, 2018 | libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpe... |
| CVE-2018-19662 | — | — | 2.3% | Nov 29, 2018 | An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that wi... |
| CVE-2018-19661 | — | — | 2.1% | Nov 29, 2018 | An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that wi... |
| CVE-2018-19655 | — | — | 2.9% | Nov 29, 2018 | A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other ... |
| CVE-2018-19654 | HIGH | 7.5 | 0.9% | Nov 29, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in userna... |
| CVE-2018-19628 | — | — | 3.1% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl... |
| CVE-2018-19627 | — | — | 17.7% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v... |
| CVE-2018-19626 | — | — | 1.4% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/p... |
| CVE-2018-19625 | — | — | 1.4% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_co... |
| CVE-2018-19624 | — | — | 1.4% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/p... |
| CVE-2018-19623 | — | — | 4.2% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could ... |
| CVE-2018-19622 | — | — | 3.2% | Nov 29, 2018 | In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed i... |
| CVE-2018-18203 | — | — | 0.2% | Nov 28, 2018 | A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (... |
| CVE-2018-17930 | CRITICAL | 9.8 | 7.3% | Nov 28, 2018 | A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, wh... |
| CVE-2018-19651 | — | — | 0.8% | Nov 28, 2018 | admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=... |
| CVE-2018-19370 | — | — | 3.2% | Nov 28, 2018 | A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) ... |
| CVE-2018-5559 | LOW | 3.4 | 0.6% | Nov 28, 2018 | In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connecti... |
| CVE-2018-19646 | — | — | 3.5% | Nov 28, 2018 | The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute ar... |
| CVE-2018-15441 | CRITICAL | 9.4 | 3.7% | Nov 28, 2018 | A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote at... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now