2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3914 | HIGH | 7.8 | 0.4% | Sep 21, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT... |
| CVE-2018-3913 | MEDIUM | 6.7 | 0.4% | Sep 21, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT... |
| CVE-2018-3906 | HIGH | 8.2 | 0.4% | Sep 21, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTT... |
| CVE-2018-3894 | HIGH | 8.8 | 1.8% | Sep 21, 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa... |
| CVE-2018-16786 | — | — | 0.7% | Sep 21, 2018 | DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php. |
| CVE-2018-16784 | — | — | 2.3% | Sep 21, 2018 | DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring... |
| CVE-2018-11241 | — | — | 3.7% | Sep 21, 2018 | An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary f... |
| CVE-2018-11240 | — | — | 2.3% | Sep 21, 2018 | An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' fea... |
| CVE-2018-3877 | CRITICAL | 9.9 | 1.8% | Sep 21, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-3876 | HIGH | 8.8 | 1.9% | Sep 21, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-3874 | CRITICAL | 9.9 | 1.8% | Sep 21, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-3873 | CRITICAL | 9.9 | 1.8% | Sep 21, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-8023 | — | — | 3.1% | Sep 21, 2018 | Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Ap... |
| CVE-2018-1711 | HIGH | 8.4 | 0.4% | Sep 21, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ... |
| CVE-2018-1710 | HIGH | 8.4 | 0.5% | Sep 21, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffe... |
| CVE-2018-1685 | — | — | 0.4% | Sep 21, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in ... |
| CVE-2018-14645 | HIGH | 7.5 | 3.0% | Sep 21, 2018 | A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read acc... |
| CVE-2018-14643 | CRITICAL | 9.8 | 6.0% | Sep 21, 2018 | An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can u... |
| CVE-2018-17302 | — | — | 0.6% | Sep 21, 2018 | Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message. |
| CVE-2018-17301 | — | — | 0.7% | Sep 21, 2018 | Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search p... |
| CVE-2018-17300 | MEDIUM | 4.8 | 0.6% | Sep 21, 2018 | Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section na... |
| CVE-2018-17298 | — | — | 1.8% | Sep 21, 2018 | An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its... |
| CVE-2018-17297 | — | — | 2.7% | Sep 21, 2018 | The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via dire... |
| CVE-2018-17294 | — | — | 2.7% | Sep 21, 2018 | The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's l... |
| CVE-2018-17293 | — | — | 1.6% | Sep 21, 2018 | An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether the... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now