2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14598 | — | — | 4.8% | Aug 24, 2018 | An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in ... |
| CVE-2018-11749 | — | — | 0.8% | Aug 24, 2018 | When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext t... |
| CVE-2018-15809 | — | — | 0.2% | Aug 23, 2018 | AccuPOS 2017.8 is installed with the insecure "Authenticated Users: Modify" permission for files within the installation... |
| CVE-2018-15808 | — | — | 2.3% | Aug 23, 2018 | POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM... |
| CVE-2018-15807 | — | — | 0.3% | Aug 23, 2018 | POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's... |
| CVE-2018-6558 | — | — | 0.6% | Aug 23, 2018 | The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values... |
| CVE-2018-14786 | — | — | 3.1% | Aug 23, 2018 | Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris... |
| CVE-2018-1159 | — | — | 2.5% | Aug 23, 2018 | Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory corruption vulnerability. An authenticated remote a... |
| CVE-2018-1158 | — | — | 2.5% | Aug 23, 2018 | Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a stack exhaustion vulnerability. An authenticated remote at... |
| CVE-2018-1157 | — | — | 4.4% | Aug 23, 2018 | Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability. An authenticated remote a... |
| CVE-2018-1156 | — | — | 7.4% | Aug 23, 2018 | Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface.... |
| CVE-2018-1999047 | — | — | 0.8% | Aug 23, 2018 | A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java tha... |
| CVE-2018-1999046 | — | — | 1.3% | Aug 23, 2018 | A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.j... |
| CVE-2018-1999045 | — | — | 0.9% | Aug 23, 2018 | A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, ... |
| CVE-2018-1999044 | — | — | 1.2% | Aug 23, 2018 | A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows a... |
| CVE-2018-1999043 | — | — | 1.7% | Aug 23, 2018 | A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.... |
| CVE-2018-1999042 | — | — | 1.5% | Aug 23, 2018 | A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have ... |
| CVE-2018-15804 | — | — | 1.0% | Aug 23, 2018 | An issue was discovered in the MapR File System in MapR Converged Data Platform and MapR-XD 6.x and earlier. Under certa... |
| CVE-2018-8028 | — | — | 1.3% | Aug 23, 2018 | An authenticated user can execute ALTER TABLE EXCHANGE PARTITIONS without being authorized by Apache Sentry before 2.0.1... |
| CVE-2018-15748 | — | — | 1.1% | Aug 23, 2018 | On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware ... |
| CVE-2018-15685 | — | — | 10.4% | Aug 23, 2018 | GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindow... |
| CVE-2018-11758 | — | — | 3.0% | Aug 22, 2018 | This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler... |
| CVE-2018-14801 | — | — | 0.4% | Aug 22, 2018 | In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both t... |
| CVE-2018-14799 | — | — | 0.5% | Aug 22, 2018 | In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device d... |
| CVE-2018-5238 | — | — | 1.6% | Aug 22, 2018 | Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerabil... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now