2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18561 | — | — | 0.7% | Nov 20, 2018 | An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h23... |
| CVE-2018-18440 | — | — | 0.6% | Nov 20, 2018 | DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem ... |
| CVE-2018-18439 | CRITICAL | 9.8 | 2.0% | Nov 20, 2018 | DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traf... |
| CVE-2018-16224 | — | — | 6.6% | Nov 20, 2018 | Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to ret... |
| CVE-2018-16223 | — | — | 2.1% | Nov 20, 2018 | Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application th... |
| CVE-2018-16222 | — | — | 0.5% | Nov 20, 2018 | Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.... |
| CVE-2018-12038 | — | — | 0.6% | Nov 20, 2018 | An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key... |
| CVE-2018-12037 | — | — | 0.2% | Nov 20, 2018 | An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA... |
| CVE-2018-17948 | — | — | 0.6% | Nov 20, 2018 | An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3. |
| CVE-2018-1779 | HIGH | 7.5 | 2.5% | Nov 20, 2018 | IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not ... |
| CVE-2018-19367 | — | — | 1.5% | Nov 20, 2018 | Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already crea... |
| CVE-2018-19335 | — | — | 0.4% | Nov 20, 2018 | Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b... |
| CVE-2018-19334 | — | — | 0.3% | Nov 20, 2018 | Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b... |
| CVE-2018-10099 | — | — | 0.3% | Nov 20, 2018 | Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b... |
| CVE-2018-17906 | HIGH | 8.8 | 0.8% | Nov 19, 2018 | Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials ... |
| CVE-2018-9209 | — | — | 1.8% | Nov 19, 2018 | Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2 |
| CVE-2018-9207 | — | — | 3.5% | Nov 19, 2018 | Arbitrary file upload in jQuery Upload File <= 4.0.2 |
| CVE-2018-1841 | MEDIUM | 6.2 | 0.4% | Nov 19, 2018 | IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/mas... |
| CVE-2018-17190 | — | — | 8.7% | Nov 19, 2018 | In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then r... |
| CVE-2018-15761 | CRITICAL | 9.9 | 1.7% | Nov 19, 2018 | Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which... |
| CVE-2018-15759 | CRITICAL | 9.1 | 1.7% | Nov 19, 2018 | Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials... |
| CVE-2018-18519 | — | — | 0.8% | Nov 19, 2018 | BestXsoftware Best Free Keylogger before 6.0.0 allows local users to gain privileges via a Trojan horse "%PROGRAMFILES%\... |
| CVE-2018-19355 | CRITICAL | 9.8 | 3.5% | Nov 19, 2018 | modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows... |
| CVE-2018-19358 | — | — | 0.5% | Nov 18, 2018 | GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bu... |
| CVE-2018-19353 | — | — | 1.1% | Nov 18, 2018 | The ansilove_ansi function in loaders/ansi.c in libansilove 1.0.0 allows remote attackers to cause a denial of service (... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now