2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10497 | — | — | 0.3% | Sep 24, 2018 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Email Fixed in v... |
| CVE-2018-10496 | — | — | 2.5% | Sep 24, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Internet Bro... |
| CVE-2018-17281 | — | — | 53.4% | Sep 24, 2018 | There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x throu... |
| CVE-2018-17107 | — | — | 1.6% | Sep 24, 2018 | In Tgstation tgstation-server 3.2.4.0 through 3.2.1.0 (fixed in 3.2.5.0), active logins would be cached, allowing subseq... |
| CVE-2018-16299 | — | — | 43.7% | Sep 24, 2018 | The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter. |
| CVE-2018-16283 | — | — | 63.1% | Sep 24, 2018 | The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter. |
| CVE-2018-13140 | — | — | 6.6% | Sep 24, 2018 | Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveragi... |
| CVE-2018-12975 | — | — | 1.3% | Sep 24, 2018 | The random() function of the smart contract implementation for CryptoSaga, an Ethereum game, generates a random value wi... |
| CVE-2018-14825 | — | — | 0.8% | Sep 24, 2018 | On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK... |
| CVE-2018-17439 | — | — | 1.3% | Sep 24, 2018 | An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_exten... |
| CVE-2018-17438 | — | — | 1.7% | Sep 24, 2018 | A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during ... |
| CVE-2018-17437 | — | — | 1.5% | Sep 24, 2018 | Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attack... |
| CVE-2018-17436 | — | — | 1.3% | Sep 24, 2018 | ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid... |
| CVE-2018-17435 | — | — | 1.3% | Sep 24, 2018 | A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers ... |
| CVE-2018-17434 | — | — | 2.0% | Sep 24, 2018 | A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library d... |
| CVE-2018-17433 | — | — | 1.3% | Sep 24, 2018 | A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers ... |
| CVE-2018-17432 | — | — | 1.3% | Sep 24, 2018 | A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attacke... |
| CVE-2018-17404 | — | — | 0.9% | Sep 23, 2018 | The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow an attacker to sniff private informa... |
| CVE-2018-17403 | — | — | 1.3% | Sep 23, 2018 | The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to impersona... |
| CVE-2018-17402 | — | — | 1.1% | Sep 23, 2018 | The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover ... |
| CVE-2018-17401 | — | — | 1.2% | Sep 23, 2018 | The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform A... |
| CVE-2018-17400 | — | — | 0.3% | Sep 23, 2018 | The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform A... |
| CVE-2018-17369 | — | — | 0.5% | Sep 23, 2018 | An issue was discovered in springboot_authority through 2017-03-06. There is stored XSS via the admin/role/edit roleKey,... |
| CVE-2018-17368 | — | — | 1.2% | Sep 23, 2018 | An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different dependi... |
| CVE-2018-17407 | — | — | 2.1% | Sep 23, 2018 | An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buf... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now