2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14828 | — | — | 0.4% | Oct 23, 2018 | Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to... |
| CVE-2018-14820 | — | — | 2.2% | Oct 23, 2018 | Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path ... |
| CVE-2018-14816 | CRITICAL | 9.8 | 4.1% | Oct 23, 2018 | Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified,... |
| CVE-2018-14806 | — | — | 4.8% | Oct 23, 2018 | Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrar... |
| CVE-2018-18626 | — | — | 0.9% | Oct 23, 2018 | An issue was discovered in PHPYun V4.6. There is a vulnerability that can delete any file or directory via the "admin/in... |
| CVE-2018-18622 | — | — | 0.7% | Oct 23, 2018 | An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username para... |
| CVE-2018-18608 | — | — | 2.6% | Oct 23, 2018 | DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is u... |
| CVE-2018-8569 | — | — | 13.3% | Oct 23, 2018 | A remote code execution vulnerability exists in the Yammer desktop application due to the loading of arbitrary content, ... |
| CVE-2018-18607 | — | — | 2.2% | Oct 23, 2018 | An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as ... |
| CVE-2018-18606 | — | — | 2.2% | Oct 23, 2018 | An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd... |
| CVE-2018-18605 | — | — | 2.3% | Oct 23, 2018 | A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File D... |
| CVE-2018-18589 | MEDIUM | 6.3 | 1.7% | Oct 23, 2018 | A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring softw... |
| CVE-2018-18603 | — | — | 0.9% | Oct 23, 2018 | 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.s... |
| CVE-2018-18599 | — | — | 1.5% | Oct 23, 2018 | Stegdetect through 2018-05-26 has an out-of-bounds write in f5_compress in the f5.c file. |
| CVE-2018-16837 | HIGH | 7.8 | 0.4% | Oct 23, 2018 | Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable sit... |
| CVE-2018-7911 | — | — | 0.2% | Oct 23, 2018 | Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C0... |
| CVE-2018-18329 | — | — | 0.6% | Oct 23, 2018 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer... |
| CVE-2018-18328 | — | — | 0.6% | Oct 23, 2018 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer... |
| CVE-2018-18327 | — | — | 0.6% | Oct 23, 2018 | A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer... |
| CVE-2018-15367 | — | — | 0.6% | Oct 23, 2018 | A ctl_set KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (... |
| CVE-2018-15366 | — | — | 0.5% | Oct 23, 2018 | A UrlfWTPPagePtr KERedirect Use-After-Free Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer... |
| CVE-2018-13402 | — | — | 1.4% | Oct 23, 2018 | Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 befor... |
| CVE-2018-13401 | — | — | 1.4% | Oct 23, 2018 | The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from versi... |
| CVE-2018-13400 | — | — | 1.4% | Oct 23, 2018 | Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from v... |
| CVE-2018-18587 | — | — | 0.5% | Oct 23, 2018 | BigProf AppGini 5.70 stores the passwords in the database using the MD5 hash. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now