2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-4404 | HIGH | 8.8 | 13.9% | Jan 11, 2019 | In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve... |
| CVE-2018-15460 | HIGH | 8.6 | 2.5% | Jan 10, 2019 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ES... |
| CVE-2018-15453 | HIGH | 8.6 | 2.3% | Jan 10, 2019 | A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Publi... |
| CVE-2018-0474 | HIGH | 8.8 | 1.5% | Jan 10, 2019 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticat... |
| CVE-2018-0181 | HIGH | 7.3 | 2.2% | Jan 10, 2019 | A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Ro... |
| CVE-2018-16202 | HIGH | 8.6 | 3.3% | Jan 9, 2019 | Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2... |
| CVE-2018-16177 | HIGH | 7.8 | 0.4% | Jan 9, 2019 | Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measu... |
| CVE-2018-1000412 | HIGH | 8.8 | 1.2% | Jan 9, 2019 | An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows att... |
| CVE-2018-20679 | HIGH | 7.5 | 7.9% | Jan 9, 2019 | An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server... |
| CVE-2018-2484 | HIGH | 8.8 | 1.4% | Jan 8, 2019 | SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.... |
| CVE-2018-1320 | HIGH | 7.5 | 8.2% | Jan 7, 2019 | Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the... |
| CVE-2018-5410 | HIGH | 7.8 | 1.6% | Jan 7, 2019 | Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys dri... |
| CVE-2018-16882 | HIGH | 8.8 | 0.4% | Jan 3, 2019 | A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1... |
| CVE-2018-6347 | HIGH | 7.5 | 1.4% | Dec 31, 2018 | An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affe... |
| CVE-2018-6346 | HIGH | 7.5 | 1.4% | Dec 31, 2018 | A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular... |
| CVE-2018-6344 | HIGH | 7.5 | 1.9% | Dec 31, 2018 | A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulner... |
| CVE-2018-6343 | HIGH | 7.5 | 0.8% | Dec 31, 2018 | Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of serv... |
| CVE-2018-6340 | HIGH | 8.1 | 1.4% | Dec 31, 2018 | The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires con... |
| CVE-2018-6337 | HIGH | 7.5 | 1.8% | Dec 31, 2018 | folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in m... |
| CVE-2018-6336 | HIGH | 7.8 | 0.5% | Dec 31, 2018 | An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks... |
| CVE-2018-6335 | HIGH | 7.5 | 1.5% | Dec 31, 2018 | A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to ... |
| CVE-2018-18601 | HIGH | 8.1 | 1.2% | Dec 31, 2018 | The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmwa... |
| CVE-2018-18600 | HIGH | 8.1 | 1.6% | Dec 31, 2018 | The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parame... |
| CVE-2018-20618 | HIGH | 8.8 | 1.4% | Dec 31, 2018 | ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c. |
| CVE-2018-20549 | HIGH | 8.8 | 1.8% | Dec 28, 2018 | There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now