2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1334 | — | — | 0.5% | Jul 12, 2018 | In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different l... |
| CVE-2018-13999 | — | — | 0.5% | Jul 12, 2018 | Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administ... |
| CVE-2018-13998 | — | — | 0.7% | Jul 12, 2018 | ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users. |
| CVE-2018-13997 | — | — | 1.5% | Jul 12, 2018 | Genann through 2018-07-08 has a SEGV in genann_run in genann.c. |
| CVE-2018-13996 | — | — | 1.8% | Jul 12, 2018 | Genann through 2018-07-08 has a stack-based buffer over-read in genann_train in genann.c. |
| CVE-2018-11049 | — | — | 0.4% | Jul 11, 2018 | RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled searc... |
| CVE-2018-11045 | — | — | 0.9% | Jul 11, 2018 | Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a st... |
| CVE-2018-0042 | — | — | 1.1% | Jul 11, 2018 | Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnera... |
| CVE-2018-0038 | — | — | 1.1% | Jul 11, 2018 | Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with h... |
| CVE-2018-10635 | — | — | 5.1% | Jul 11, 2018 | In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbi... |
| CVE-2018-10633 | — | — | 1.8% | Jul 11, 2018 | Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow a... |
| CVE-2018-10231 | — | — | 0.8% | Jul 11, 2018 | Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote... |
| CVE-2018-13989 | — | — | 3.2% | Jul 11, 2018 | Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable... |
| CVE-2018-11529 | — | — | 40.6% | Jul 11, 2018 | VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arb... |
| CVE-2018-10197 | — | — | 1.5% | Jul 11, 2018 | There is a time-based blind SQL injection vulnerability in the Access Manager component before 9.18.040 and 10.x before ... |
| CVE-2018-8007 | — | — | 11.7% | Jul 11, 2018 | Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of adm... |
| CVE-2018-0500 | — | — | 6.4% | Jul 11, 2018 | Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that mig... |
| CVE-2018-13879 | — | — | 0.6% | Jul 11, 2018 | A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, t... |
| CVE-2018-13878 | — | — | 0.8% | Jul 11, 2018 | An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a u... |
| CVE-2018-8356 | — | — | 0.7% | Jul 11, 2018 | A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certif... |
| CVE-2018-8326 | — | — | 2.4% | Jul 11, 2018 | A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Feder... |
| CVE-2018-8325 | — | — | 5.7% | Jul 11, 2018 | An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ... |
| CVE-2018-8324 | — | — | 9.3% | Jul 11, 2018 | An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ... |
| CVE-2018-8323 | — | — | 2.3% | Jul 11, 2018 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2018-8319 | — | — | 7.0% | Jul 11, 2018 | A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithm... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now