2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1784 | HIGH | 7.1 | 1.7% | Dec 20, 2018 | IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IB... |
| CVE-2018-1778 | HIGH | 7.7 | 3.4% | Dec 20, 2018 | IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication i... |
| CVE-2018-1771 | HIGH | 8.4 | 0.5% | Dec 20, 2018 | IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in th... |
| CVE-2018-8653 | HIGH | 7.5 | 29.1% | Dec 20, 2018 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2018-15801 | HIGH | 7.4 | 0.7% | Dec 19, 2018 | Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation... |
| CVE-2018-15798 | HIGH | 7.6 | 1.1% | Dec 19, 2018 | Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unau... |
| CVE-2018-18999 | HIGH | 7.3 | 2.3% | Dec 19, 2018 | WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user suppl... |
| CVE-2018-20227 | HIGH | 7.5 | 1.8% | Dec 19, 2018 | RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive. |
| CVE-2018-16884 | HIGH | 8 | 1.5% | Dec 18, 2018 | A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the sa... |
| CVE-2018-4015 | HIGH | 8.1 | 0.7% | Dec 18, 2018 | An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration o... |
| CVE-2018-20196 | HIGH | 7.8 | 1.3% | Dec 18, 2018 | There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Fr... |
| CVE-2018-16874 | HIGH | 8.1 | 5.0% | Dec 14, 2018 | In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed wi... |
| CVE-2018-16873 | HIGH | 8.1 | 66.3% | Dec 14, 2018 | In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed ... |
| CVE-2018-1821 | HIGH | 7.1 | 15.8% | Dec 13, 2018 | IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a... |
| CVE-2018-16557 | HIGH | 8.2 | 0.8% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (... |
| CVE-2018-16556 | HIGH | 7.5 | 1.5% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (... |
| CVE-2018-20127 | HIGH | 7.5 | 1.4% | Dec 13, 2018 | An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary fil... |
| CVE-2018-6706 | HIGH | 7.5 | 0.6% | Dec 12, 2018 | Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivi... |
| CVE-2018-6705 | HIGH | 7.8 | 0.4% | Dec 12, 2018 | Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local use... |
| CVE-2018-6704 | HIGH | 7.8 | 0.4% | Dec 12, 2018 | Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local use... |
| CVE-2018-16867 | HIGH | 7.8 | 0.4% | Dec 12, 2018 | A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_da... |
| CVE-2018-8639 | HIGH | 7.8 | 22.3% | Dec 12, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2018-8611 | HIGH | 7.8 | 4.2% | Dec 12, 2018 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "... |
| CVE-2018-2503 | HIGH | 7.4 | 0.6% | Dec 11, 2018 | By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that shoul... |
| CVE-2018-2492 | HIGH | 7.1 | 1.1% | Dec 11, 2018 | SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now