2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19274 | HIGH | 7.2 | 5.2% | Nov 17, 2018 | Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Inject... |
| CVE-2018-15769 | HIGH | 7.5 | 2.6% | Nov 16, 2018 | RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series)... |
| CVE-2018-7362 | HIGH | 7.5 | 1.2% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which ma... |
| CVE-2018-19296 | HIGH | 8.8 | 2.2% | Nov 16, 2018 | PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. |
| CVE-2018-16621 | HIGH | 7.2 | 1.8% | Nov 15, 2018 | Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection. |
| CVE-2018-6065 | HIGH | 8.8 | 58.8% | Nov 14, 2018 | Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch... |
| CVE-2018-17463 | HIGH | 8.8 | 83.9% | Nov 14, 2018 | Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit... |
| CVE-2018-3635 | HIGH | 7.8 | 0.4% | Nov 14, 2018 | Insufficient input validation in installer in Intel Rapid Store Technology (RST) before version 16.7 may allow an unpriv... |
| CVE-2018-19277 | HIGH | 8.8 | 7.8% | Nov 14, 2018 | securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 enco... |
| CVE-2018-8589 | HIGH | 7.8 | 3.0% | Nov 14, 2018 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k ... |
| CVE-2018-8581 | HIGH | 7.4 | 27.6% | Nov 14, 2018 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of... |
| CVE-2018-6980 | HIGH | 7.2 | 1.4% | Nov 13, 2018 | VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authori... |
| CVE-2018-14657 | HIGH | 8.1 | 1.2% | Nov 13, 2018 | A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force ... |
| CVE-2018-12416 | HIGH | 7.1 | 0.6% | Nov 13, 2018 | The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager c... |
| CVE-2018-1792 | HIGH | 8.8 | 0.5% | Nov 13, 2018 | IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local... |
| CVE-2018-15795 | HIGH | 8.1 | 1.3% | Nov 13, 2018 | Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating s... |
| CVE-2018-19183 | HIGH | 7.5 | 3.1% | Nov 12, 2018 | ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.fr... |
| CVE-2018-15796 | HIGH | 8.1 | 0.7% | Nov 9, 2018 | Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote ... |
| CVE-2018-1834 | HIGH | 7.4 | 0.4% | Nov 9, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha... |
| CVE-2018-1802 | HIGH | 8.4 | 0.4% | Nov 9, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared librari... |
| CVE-2018-1781 | HIGH | 8.4 | 0.5% | Nov 9, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ... |
| CVE-2018-1780 | HIGH | 7.8 | 0.5% | Nov 9, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 inst... |
| CVE-2018-1774 | HIGH | 8.9 | 1.1% | Nov 9, 2018 | IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analyt... |
| CVE-2018-15448 | HIGH | 7.5 | 2.2% | Nov 8, 2018 | A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, re... |
| CVE-2018-19093 | HIGH | 7.5 | 1.7% | Nov 7, 2018 | An issue has been found in libIEC61850 v1.3. It is a SEGV in ControlObjectClient_setCommandTerminationHandler in client/... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now