2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16855 | HIGH | 7.5 | 59.5% | Dec 3, 2018 | An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigge... |
| CVE-2018-4040 | HIGH | 7.8 | 1.0% | Dec 1, 2018 | An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, ver... |
| CVE-2018-4039 | HIGH | 7.8 | 1.4% | Dec 1, 2018 | An exploitable out-of-bounds write vulnerability exists in the PNG implementation of Atlantis Word Processor, version 3.... |
| CVE-2018-4038 | HIGH | 7.8 | 1.3% | Dec 1, 2018 | An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, v... |
| CVE-2018-3951 | HIGH | 7.2 | 3.9% | Dec 1, 2018 | An exploitable remote code execution vulnerability exists in the HTTP header-parsing function of the TP-Link TL-R600VPN ... |
| CVE-2018-3950 | HIGH | 8.8 | 2.9% | Dec 1, 2018 | An exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VP... |
| CVE-2018-3949 | HIGH | 7.5 | 53.3% | Dec 1, 2018 | An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A... |
| CVE-2018-3948 | HIGH | 7.5 | 23.1% | Nov 30, 2018 | An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP se... |
| CVE-2018-1897 | HIGH | 8.4 | 0.6% | Nov 30, 2018 | IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, ... |
| CVE-2018-19654 | HIGH | 7.5 | 0.9% | Nov 29, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in userna... |
| CVE-2018-12122 | HIGH | 7.5 | 41.3% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker... |
| CVE-2018-12121 | HIGH | 7.5 | 10.2% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By... |
| CVE-2018-12120 | HIGH | 8.1 | 4.3% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger... |
| CVE-2018-12116 | HIGH | 7.5 | 4.6% | Nov 28, 2018 | Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use uns... |
| CVE-2018-16857 | HIGH | 7.4 | 2.3% | Nov 28, 2018 | Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict... |
| CVE-2018-16853 | HIGH | 7.5 | 3.1% | Nov 28, 2018 | Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is buil... |
| CVE-2018-0721 | HIGH | 7.7 | 1.6% | Nov 27, 2018 | Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Syste... |
| CVE-2018-17953 | HIGH | 7.5 | 1.3% | Nov 27, 2018 | A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE L... |
| CVE-2018-18807 | HIGH | 7.6 | 1.2% | Nov 26, 2018 | The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerab... |
| CVE-2018-1905 | HIGH | 7.1 | 2.5% | Nov 26, 2018 | IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack w... |
| CVE-2018-19518 | HIGH | 7.5 | 95.2% | Nov 25, 2018 | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c... |
| CVE-2018-19423 | HIGH | 7.2 | 18.0% | Nov 21, 2018 | Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file. |
| CVE-2018-19422 | HIGH | 7.2 | 65.1% | Nov 21, 2018 | /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca... |
| CVE-2018-1779 | HIGH | 7.5 | 2.5% | Nov 20, 2018 | IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not ... |
| CVE-2018-17906 | HIGH | 8.8 | 0.8% | Nov 19, 2018 | Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now