2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1904 | HIGH | 8.1 | 3.7% | Dec 11, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code thro... |
| CVE-2018-17480 | HIGH | 8.8 | 34.3% | Dec 11, 2018 | Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chr... |
| CVE-2018-15800 | HIGH | 8.1 | 0.9% | Dec 10, 2018 | Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicio... |
| CVE-2018-1279 | HIGH | 8.5 | 1.8% | Dec 10, 2018 | Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines wh... |
| CVE-2018-20004 | HIGH | 8.8 | 2.0% | Dec 10, 2018 | An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file... |
| CVE-2018-9577 | HIGH | 7.8 | 0.9% | Dec 7, 2018 | In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to... |
| CVE-2018-9576 | HIGH | 7.8 | 0.9% | Dec 7, 2018 | In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to mi... |
| CVE-2018-9575 | HIGH | 7.8 | 0.9% | Dec 7, 2018 | In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bo... |
| CVE-2018-9574 | HIGH | 7.8 | 0.9% | Dec 7, 2018 | In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missi... |
| CVE-2018-9573 | HIGH | 7.8 | 0.9% | Dec 7, 2018 | In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds che... |
| CVE-2018-9572 | HIGH | 8.8 | 1.1% | Dec 7, 2018 | In impd_drc_parse_coeff of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check... |
| CVE-2018-9571 | HIGH | 8.8 | 1.1% | Dec 7, 2018 | In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing b... |
| CVE-2018-9570 | HIGH | 7.8 | 0.9% | Dec 7, 2018 | In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds chec... |
| CVE-2018-9569 | HIGH | 8.8 | 1.1% | Dec 7, 2018 | In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect b... |
| CVE-2018-5802 | HIGH | 8.8 | 2.0% | Dec 7, 2018 | An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw... |
| CVE-2018-16861 | HIGH | 7.6 | 0.9% | Dec 7, 2018 | A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create ... |
| CVE-2018-1920 | HIGH | 7.1 | 2.4% | Dec 7, 2018 | IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processi... |
| CVE-2018-1424 | HIGH | 7.1 | 2.4% | Dec 7, 2018 | IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when process... |
| CVE-2018-17924 | HIGH | 8.6 | 4.3% | Dec 7, 2018 | Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote ... |
| CVE-2018-19939 | HIGH | 7.5 | 1.3% | Dec 7, 2018 | The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite... |
| CVE-2018-19935 | HIGH | 7.5 | 6.9% | Dec 7, 2018 | ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer d... |
| CVE-2018-19931 | HIGH | 7.8 | 1.5% | Dec 7, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through... |
| CVE-2018-6757 | HIGH | 7.5 | 1.1% | Dec 6, 2018 | Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows loca... |
| CVE-2018-6756 | HIGH | 7.8 | 1.0% | Dec 6, 2018 | Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows loca... |
| CVE-2018-6755 | HIGH | 7.2 | 1.0% | Dec 6, 2018 | Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now