2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14653 | HIGH | 8.8 | 2.8% | Oct 31, 2018 | The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_g... |
| CVE-2018-1851 | HIGH | 7.3 | 3.9% | Oct 31, 2018 | IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the s... |
| CVE-2018-16469 | HIGH | 7.5 | 1.7% | Oct 30, 2018 | The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Objec... |
| CVE-2018-4022 | HIGH | 7.8 | 1.5% | Oct 26, 2018 | A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A sp... |
| CVE-2018-15688 | HIGH | 8.8 | 1.7% | Oct 26, 2018 | A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory ... |
| CVE-2018-15687 | HIGH | 7 | 1.1% | Oct 26, 2018 | A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary... |
| CVE-2018-15686 | HIGH | 7.8 | 2.3% | Oct 26, 2018 | A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution ... |
| CVE-2018-3971 | HIGH | 7.8 | 0.5% | Oct 25, 2018 | An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Aler... |
| CVE-2018-17921 | HIGH | 8.8 | 0.7% | Oct 24, 2018 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair... |
| CVE-2018-15442 | HIGH | 7.8 | 16.0% | Oct 24, 2018 | A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, loca... |
| CVE-2018-11804 | HIGH | 7.5 | 5.7% | Oct 24, 2018 | Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to sp... |
| CVE-2018-17935 | HIGH | 8.1 | 0.7% | Oct 24, 2018 | All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and r... |
| CVE-2018-16837 | HIGH | 7.8 | 0.4% | Oct 23, 2018 | Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable sit... |
| CVE-2018-18559 | HIGH | 8.1 | 2.6% | Oct 22, 2018 | In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt ... |
| CVE-2018-1850 | HIGH | 8.8 | 2.2% | Oct 22, 2018 | IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations wh... |
| CVE-2018-15756 | HIGH | 7.5 | 9.5% | Oct 18, 2018 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported ver... |
| CVE-2018-11080 | HIGH | 7.3 | 0.4% | Oct 18, 2018 | Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The ap... |
| CVE-2018-0443 | HIGH | 7.5 | 3.4% | Oct 17, 2018 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless ... |
| CVE-2018-0442 | HIGH | 7.5 | 3.3% | Oct 17, 2018 | A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless ... |
| CVE-2018-0441 | HIGH | 7.4 | 0.9% | Oct 17, 2018 | A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unau... |
| CVE-2018-0417 | HIGH | 7.8 | 3.2% | Oct 17, 2018 | A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated,... |
| CVE-2018-0378 | HIGH | 8.6 | 4.5% | Oct 17, 2018 | A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running... |
| CVE-2018-0456 | HIGH | 7.7 | 3.2% | Oct 17, 2018 | A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could al... |
| CVE-2018-18445 | HIGH | 7.8 | 0.5% | Oct 17, 2018 | In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in t... |
| CVE-2018-0395 | HIGH | 8.8 | 0.9% | Oct 17, 2018 | A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Softw... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now