2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3984 | HIGH | 7.8 | 1.4% | Oct 1, 2018 | An exploitable uninitialized length vulnerability exists within the Word document-parser of the Atlantis Word Processor ... |
| CVE-2018-3982 | HIGH | 7.8 | 1.3% | Oct 1, 2018 | An exploitable arbitrary write vulnerability exists in the Word document parser of the Atlantis Word Processor 3.0.2.3 a... |
| CVE-2018-3981 | HIGH | 7.8 | 2.3% | Oct 1, 2018 | An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. An attacker ca... |
| CVE-2018-3978 | HIGH | 8.8 | 1.0% | Oct 1, 2018 | An exploitable out-of-bounds write vulnerability exists in the Word Document parser of the Atlantis Word Processor 3.0.2... |
| CVE-2018-3975 | HIGH | 7.5 | 1.2% | Oct 1, 2018 | An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3... |
| CVE-2018-15702 | — | — | 0.5% | Oct 1, 2018 | The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the r... |
| CVE-2018-15701 | — | — | 0.6% | Oct 1, 2018 | The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated ... |
| CVE-2018-15700 | — | — | 0.6% | Oct 1, 2018 | The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated ... |
| CVE-2018-10605 | — | — | 1.5% | Oct 1, 2018 | Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system conf... |
| CVE-2018-14808 | — | — | 0.9% | Oct 1, 2018 | Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on ... |
| CVE-2018-14804 | — | — | 3.5% | Oct 1, 2018 | Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code exec... |
| CVE-2018-1672 | MEDIUM | 5 | 1.2% | Oct 1, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios,... |
| CVE-2018-1420 | MEDIUM | 5.3 | 1.3% | Oct 1, 2018 | IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Co... |
| CVE-2018-14802 | — | — | 3.6% | Oct 1, 2018 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA,... |
| CVE-2018-14798 | — | — | 1.3% | Oct 1, 2018 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA,... |
| CVE-2018-14794 | — | — | 1.9% | Oct 1, 2018 | Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a pr... |
| CVE-2018-14790 | — | — | 5.4% | Oct 1, 2018 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA,... |
| CVE-2018-14788 | — | — | 1.4% | Oct 1, 2018 | Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. A buffer overflow information disclosure vulnerability occurs ... |
| CVE-2018-17854 | — | — | 1.5% | Oct 1, 2018 | SIMDComp before 0.1.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application ... |
| CVE-2018-17852 | — | — | 1.5% | Oct 1, 2018 | A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to ... |
| CVE-2018-17851 | — | — | — | Oct 1, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-17850 | — | — | — | Oct 1, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-17848 | HIGH | 7.5 | 2.7% | Oct 1, 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "... |
| CVE-2018-17847 | HIGH | 7.5 | 2.8% | Oct 1, 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading ... |
| CVE-2018-17846 | HIGH | 7.5 | 2.6% | Oct 1, 2018 | The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now