2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18227 | — | — | 3.1% | Oct 12, 2018 | In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/di... |
| CVE-2018-18226 | — | — | 3.2% | Oct 12, 2018 | In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/d... |
| CVE-2018-18225 | HIGH | 7.5 | 2.9% | Oct 12, 2018 | In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensu... |
| CVE-2018-1838 | MEDIUM | 5.3 | 1.6% | Oct 12, 2018 | IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information ... |
| CVE-2018-1673 | MEDIUM | 6.1 | 1.3% | Oct 12, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em... |
| CVE-2018-17929 | HIGH | 7.8 | 1.8% | Oct 11, 2018 | In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerab... |
| CVE-2018-17927 | — | — | 2.1% | Oct 11, 2018 | In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities ... |
| CVE-2018-12441 | — | — | 0.5% | Oct 11, 2018 | The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unpriv... |
| CVE-2018-18258 | — | — | 1.5% | Oct 11, 2018 | An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any... |
| CVE-2018-18257 | — | — | 1.6% | Oct 11, 2018 | An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.ph... |
| CVE-2018-15766 | — | — | 0.6% | Oct 11, 2018 | On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will ... |
| CVE-2018-9206 | CRITICAL | 9.8 | 97.1% | Oct 11, 2018 | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 |
| CVE-2018-18215 | — | — | 0.5% | Oct 11, 2018 | In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account. |
| CVE-2018-18242 | — | — | 1.1% | Oct 11, 2018 | youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=logi... |
| CVE-2018-12449 | — | — | 0.9% | Oct 11, 2018 | The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking. |
| CVE-2018-1745 | HIGH | 7.5 | 3.9% | Oct 11, 2018 | IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to mis... |
| CVE-2018-1738 | HIGH | 7.1 | 1.1% | Oct 11, 2018 | IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive informatio... |
| CVE-2018-1724 | MEDIUM | 5.9 | 0.3% | Oct 11, 2018 | IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time d... |
| CVE-2018-1708 | MEDIUM | 6.5 | 1.2% | Oct 11, 2018 | IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as p... |
| CVE-2018-1706 | MEDIUM | 5.4 | 0.7% | Oct 11, 2018 | IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2018-18240 | — | — | 3.7% | Oct 11, 2018 | Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine co... |
| CVE-2018-18062 | — | — | 0.8% | Oct 10, 2018 | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remo... |
| CVE-2018-18061 | — | — | 0.9% | Oct 10, 2018 | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager int... |
| CVE-2018-17784 | MEDIUM | 6.1 | 4.4% | Oct 10, 2018 | Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic... |
| CVE-2018-17337 | — | — | 0.7% | Oct 10, 2018 | Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now