2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16758 | MEDIUM | 5.9 | 0.9% | Oct 10, 2018 | Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle at... |
| CVE-2018-16738 | LOW | 3.7 | 1.4% | Oct 10, 2018 | tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed i... |
| CVE-2018-16737 | MEDIUM | 5.3 | 1.5% | Oct 10, 2018 | tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation. |
| CVE-2018-13789 | — | — | 1.2% | Oct 10, 2018 | An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of file... |
| CVE-2018-12596 | — | — | 22.4% | Oct 10, 2018 | Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at... |
| CVE-2018-12456 | — | — | 0.9% | Oct 10, 2018 | Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attacker... |
| CVE-2018-12455 | — | — | 5.0% | Oct 10, 2018 | Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate... |
| CVE-2018-12544 | — | — | 2.2% | Oct 10, 2018 | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking ... |
| CVE-2018-12542 | — | — | 2.3% | Oct 10, 2018 | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that sho... |
| CVE-2018-12541 | MEDIUM | 6.5 | 2.7% | Oct 10, 2018 | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http reques... |
| CVE-2018-12410 | CRITICAL | 9.8 | 4.0% | Oct 10, 2018 | The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may... |
| CVE-2018-12193 | MEDIUM | 5.5 | 0.4% | Oct 10, 2018 | Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an u... |
| CVE-2018-12173 | — | — | 0.4% | Oct 10, 2018 | Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before fi... |
| CVE-2018-12172 | — | — | 0.3% | Oct 10, 2018 | Improper password hashing in firmware in Intel Server Board (S7200AP,S7200APR) and Intel Compute Module (HNS7200AP, HNS7... |
| CVE-2018-12161 | — | — | 1.1% | Oct 10, 2018 | Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated ... |
| CVE-2018-12158 | — | — | 0.3% | Oct 10, 2018 | Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a pri... |
| CVE-2018-12153 | — | — | 0.4% | Oct 10, 2018 | Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5... |
| CVE-2018-12152 | — | — | 0.9% | Oct 10, 2018 | Pointer corruption in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.... |
| CVE-2018-0063 | MEDIUM | 6.5 | 0.6% | Oct 10, 2018 | A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the mana... |
| CVE-2018-0062 | MEDIUM | 5.3 | 2.3% | Oct 10, 2018 | A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service wh... |
| CVE-2018-0061 | MEDIUM | 5.3 | 2.3% | Oct 10, 2018 | A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high C... |
| CVE-2018-0060 | MEDIUM | 5.3 | 1.1% | Oct 10, 2018 | An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an ... |
| CVE-2018-0059 | MEDIUM | 5.4 | 0.8% | Oct 10, 2018 | A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authentic... |
| CVE-2018-0058 | MEDIUM | 5.9 | 1.4% | Oct 10, 2018 | Receipt of a specially crafted IPv6 exception packet may be able to trigger a kernel crash (vmcore), causing the device ... |
| CVE-2018-0057 | MEDIUM | 6.1 | 1.1% | Oct 10, 2018 | On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now