2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16844 | HIGH | 7.5 | 12.4% | Nov 7, 2018 | nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive... |
| CVE-2018-16843 | HIGH | 7.5 | 47.1% | Nov 7, 2018 | nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive... |
| CVE-2018-19052 | HIGH | 7.5 | 14.1% | Nov 7, 2018 | An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ p... |
| CVE-2018-12415 | HIGH | 7.5 | 0.9% | Nov 6, 2018 | The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Ent... |
| CVE-2018-12414 | HIGH | 7.5 | 0.7% | Nov 6, 2018 | The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezv... |
| CVE-2018-12413 | HIGH | 7.5 | 0.9% | Nov 6, 2018 | The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution... |
| CVE-2018-12412 | HIGH | 7.5 | 0.9% | Nov 6, 2018 | The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer ... |
| CVE-2018-12411 | HIGH | 7.5 | 0.9% | Nov 6, 2018 | The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpa... |
| CVE-2018-16472 | HIGH | 7.5 | 2.1% | Nov 6, 2018 | A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.... |
| CVE-2018-9363 | HIGH | 8.4 | 0.4% | Nov 6, 2018 | In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no... |
| CVE-2018-16847 | HIGH | 7.8 | 0.5% | Nov 2, 2018 | An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cm... |
| CVE-2018-7798 | HIGH | 8.2 | 0.7% | Nov 2, 2018 | A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which... |
| CVE-2018-3935 | HIGH | 7.5 | 2.3% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A s... |
| CVE-2018-3899 | HIGH | 7.5 | 1.9% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D... |
| CVE-2018-3898 | HIGH | 7.5 | 1.9% | Nov 2, 2018 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D... |
| CVE-2018-3892 | HIGH | 8.1 | 2.7% | Nov 2, 2018 | An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D... |
| CVE-2018-1846 | HIGH | 7.1 | 1.9% | Nov 2, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Enti... |
| CVE-2018-1835 | HIGH | 7.1 | 1.9% | Nov 2, 2018 | IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when ... |
| CVE-2018-3977 | HIGH | 8.8 | 3.5% | Nov 1, 2018 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A speci... |
| CVE-2018-3947 | HIGH | 8.1 | 1.3% | Nov 1, 2018 | An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US ... |
| CVE-2018-3928 | HIGH | 7.5 | 2.3% | Nov 1, 2018 | An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D.... |
| CVE-2018-3910 | HIGH | 8 | 1.6% | Nov 1, 2018 | An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D.... |
| CVE-2018-3900 | HIGH | 8.8 | 2.6% | Nov 1, 2018 | An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D... |
| CVE-2018-15454 | HIGH | 8.6 | 4.4% | Nov 1, 2018 | A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) So... |
| CVE-2018-14651 | HIGH | 8.8 | 3.2% | Oct 31, 2018 | It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was inc... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now