2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18909 | — | — | 0.9% | Nov 3, 2018 | xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code ... |
| CVE-2018-18903 | — | — | 5.2% | Nov 3, 2018 | Vanilla 2.6.x before 2.6.4 allows remote code execution. |
| CVE-2018-18915 | — | — | 1.8% | Nov 3, 2018 | There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted inpu... |
| CVE-2018-16847 | HIGH | 7.8 | 0.5% | Nov 2, 2018 | An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cm... |
| CVE-2018-15762 | CRITICAL | 9 | 1.1% | Nov 2, 2018 | Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.... |
| CVE-2018-11062 | — | — | 1.8% | Nov 2, 2018 | Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin... |
| CVE-2018-16849 | LOW | 3.1 | 1.5% | Nov 2, 2018 | A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to d... |
| CVE-2018-7799 | — | — | 2.8% | Nov 2, 2018 | A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which c... |
| CVE-2018-7798 | HIGH | 8.2 | 0.7% | Nov 2, 2018 | A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which... |
| CVE-2018-3935 | HIGH | 7.5 | 2.3% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A s... |
| CVE-2018-3934 | CRITICAL | 9.8 | 2.6% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D.... |
| CVE-2018-3920 | MEDIUM | 6.8 | 0.6% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7... |
| CVE-2018-3899 | HIGH | 7.5 | 1.9% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D... |
| CVE-2018-3898 | HIGH | 7.5 | 1.9% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D... |
| CVE-2018-3892 | HIGH | 8.1 | 2.7% | Nov 2, 2018 | An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D... |
| CVE-2018-3891 | MEDIUM | 4.6 | 0.4% | Nov 2, 2018 | An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7... |
| CVE-2018-3890 | MEDIUM | 6.8 | 1.7% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D.... |
| CVE-2018-1878 | MEDIUM | 5.3 | 1.3% | Nov 2, 2018 | IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that co... |
| CVE-2018-1877 | MEDIUM | 6.2 | 0.2% | Nov 2, 2018 | IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unenc... |
| CVE-2018-1876 | MEDIUM | 6.2 | 0.4% | Nov 2, 2018 | IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control ... |
| CVE-2018-1846 | HIGH | 7.1 | 1.9% | Nov 2, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Enti... |
| CVE-2018-1835 | HIGH | 7.1 | 1.9% | Nov 2, 2018 | IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when ... |
| CVE-2018-17922 | — | — | 3.2% | Nov 2, 2018 | Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log f... |
| CVE-2018-17918 | — | — | 3.8% | Nov 2, 2018 | Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a... |
| CVE-2018-1788 | MEDIUM | 4.1 | 0.4% | Nov 2, 2018 | IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now