2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16890 | HIGH | 7.5 | 5.4% | Feb 6, 2019 | libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling i... |
| CVE-2018-18333 | HIGH | 7.8 | 1.8% | Feb 5, 2019 | A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow a... |
| CVE-2018-20250 | HIGH | 7.8 | 96.3% | Feb 5, 2019 | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o... |
| CVE-2018-11803 | HIGH | 7.5 | 57.8% | Feb 5, 2019 | Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an unin... |
| CVE-2018-15778 | HIGH | 8.8 | 0.4% | Feb 4, 2019 | Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-li... |
| CVE-2018-1970 | HIGH | 7.1 | 1.9% | Feb 4, 2019 | IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML da... |
| CVE-2018-16482 | HIGH | 7.5 | 1.8% | Feb 1, 2019 | A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to acce... |
| CVE-2018-3956 | HIGH | 7.1 | 49.6% | Jan 30, 2019 | An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Softwa... |
| CVE-2018-16880 | HIGH | 7 | 0.6% | Jan 29, 2019 | A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under ... |
| CVE-2018-19015 | HIGH | 7.3 | 1.5% | Jan 28, 2019 | An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 a... |
| CVE-2018-19009 | HIGH | 7.8 | 0.2% | Jan 25, 2019 | Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system conta... |
| CVE-2018-16881 | HIGH | 7.5 | 2.2% | Jan 25, 2019 | A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted ... |
| CVE-2018-19634 | HIGH | 7.5 | 1.3% | Jan 22, 2019 | CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey informatio... |
| CVE-2018-15784 | HIGH | 7.4 | 0.6% | Jan 18, 2019 | Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properl... |
| CVE-2018-15982 | HIGH | 7.8 | 81.8% | Jan 18, 2019 | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful... |
| CVE-2018-2019 | HIGH | 7.1 | 2.4% | Jan 18, 2019 | IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when... |
| CVE-2018-18814 | HIGH | 8.8 | 3.1% | Jan 16, 2019 | The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketpla... |
| CVE-2018-18813 | HIGH | 8.8 | 1.5% | Jan 16, 2019 | The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TI... |
| CVE-2018-5740 | HIGH | 7.5 | 59.4% | Jan 16, 2019 | "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS... |
| CVE-2018-5734 | HIGH | 7.5 | 6.2% | Jan 16, 2019 | While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcod... |
| CVE-2018-5733 | HIGH | 7.5 | 20.2% | Jan 16, 2019 | A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eve... |
| CVE-2018-15782 | HIGH | 7.7 | 0.4% | Jan 16, 2019 | The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal... |
| CVE-2018-16886 | HIGH | 8.1 | 4.0% | Jan 14, 2019 | etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-b... |
| CVE-2018-16865 | HIGH | 7.8 | 3.0% | Jan 11, 2019 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover... |
| CVE-2018-16864 | HIGH | 7.8 | 0.7% | Jan 11, 2019 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now