2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1552 | MEDIUM | 5.5 | 2.9% | Nov 2, 2018 | IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code... |
| CVE-2018-17912 | — | — | 1.6% | Nov 2, 2018 | An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow re... |
| CVE-2018-17916 | CRITICAL | 9.8 | 3.7% | Nov 2, 2018 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to... |
| CVE-2018-17914 | CRITICAL | 9.8 | 4.6% | Nov 2, 2018 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to... |
| CVE-2018-18897 | MEDIUM | 6.5 | 2.0% | Nov 2, 2018 | An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as... |
| CVE-2018-6909 | — | — | 1.1% | Nov 1, 2018 | A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web applic... |
| CVE-2018-6908 | — | — | 1.6% | Nov 1, 2018 | An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD ... |
| CVE-2018-6907 | — | — | 0.5% | Nov 1, 2018 | A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch... |
| CVE-2018-6906 | — | — | 0.7% | Nov 1, 2018 | A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and T... |
| CVE-2018-6012 | — | — | 1.3% | Nov 1, 2018 | The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject ... |
| CVE-2018-6011 | — | — | 1.1% | Nov 1, 2018 | The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2... |
| CVE-2018-18777 | — | — | 19.6% | Nov 1, 2018 | Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp... |
| CVE-2018-18776 | — | — | 2.3% | Nov 1, 2018 | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (... |
| CVE-2018-18775 | — | — | 6.6% | Nov 1, 2018 | Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (... |
| CVE-2018-18714 | — | — | 0.9% | Nov 1, 2018 | RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker ... |
| CVE-2018-18695 | — | — | 0.4% | Nov 1, 2018 | M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted... |
| CVE-2018-10587 | — | — | 3.3% | Nov 1, 2018 | NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vu... |
| CVE-2018-10586 | — | — | 0.5% | Nov 1, 2018 | NetGain Enterprise Manager (EM) is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities in versions be... |
| CVE-2018-3977 | HIGH | 8.8 | 3.5% | Nov 1, 2018 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A speci... |
| CVE-2018-3947 | HIGH | 8.1 | 1.3% | Nov 1, 2018 | An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US ... |
| CVE-2018-3928 | HIGH | 7.5 | 2.3% | Nov 1, 2018 | An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D.... |
| CVE-2018-3910 | HIGH | 8 | 1.6% | Nov 1, 2018 | An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D.... |
| CVE-2018-3900 | HIGH | 8.8 | 2.6% | Nov 1, 2018 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D... |
| CVE-2018-14660 | MEDIUM | 6.5 | 2.5% | Nov 1, 2018 | A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY x... |
| CVE-2018-7356 | MEDIUM | 5.6 | 0.7% | Nov 1, 2018 | All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vul... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now