2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1788 | MEDIUM | 4.1 | 0.4% | Nov 2, 2018 | IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged... |
| CVE-2018-1552 | MEDIUM | 5.5 | 2.9% | Nov 2, 2018 | IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code... |
| CVE-2018-18897 | MEDIUM | 6.5 | 2.0% | Nov 2, 2018 | An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as... |
| CVE-2018-14660 | MEDIUM | 6.5 | 2.5% | Nov 1, 2018 | A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY x... |
| CVE-2018-7356 | MEDIUM | 5.6 | 0.7% | Nov 1, 2018 | All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vul... |
| CVE-2018-14661 | MEDIUM | 6.5 | 2.7% | Oct 31, 2018 | It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red ... |
| CVE-2018-16842 | MEDIUM | 4.4 | 2.1% | Oct 31, 2018 | Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function ... |
| CVE-2018-14659 | MEDIUM | 6.5 | 2.2% | Oct 31, 2018 | The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_... |
| CVE-2018-14654 | MEDIUM | 6.5 | 2.6% | Oct 31, 2018 | The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attack... |
| CVE-2018-14652 | MEDIUM | 6.5 | 2.7% | Oct 31, 2018 | The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' trans... |
| CVE-2018-16839 | MEDIUM | 4.3 | 5.8% | Oct 31, 2018 | Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to ... |
| CVE-2018-18873 | MEDIUM | 5.5 | 1.4% | Oct 31, 2018 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_... |
| CVE-2018-13282 | MEDIUM | 5.6 | 1.0% | Oct 31, 2018 | Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attac... |
| CVE-2018-13281 | MEDIUM | 4.3 | 1.2% | Oct 31, 2018 | Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remo... |
| CVE-2018-0734 | MEDIUM | 5.9 | 12.2% | Oct 30, 2018 | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could u... |
| CVE-2018-17622 | MEDIUM | 6.5 | 3.0% | Oct 29, 2018 | This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader... |
| CVE-2018-1767 | MEDIUM | 6.1 | 1.4% | Oct 29, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnera... |
| CVE-2018-1766 | MEDIUM | 5.4 | 0.7% | Oct 29, 2018 | IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabilit... |
| CVE-2018-0735 | MEDIUM | 5.9 | 4.8% | Oct 29, 2018 | The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could... |
| CVE-2018-18749 | MEDIUM | 5.5 | 0.7% | Oct 29, 2018 | data-tools through 2017-07-26 has an Integer Overflow leading to an incorrect end value for the write_wchars function. |
| CVE-2018-18660 | MEDIUM | 6.1 | 0.9% | Oct 26, 2018 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Refle... |
| CVE-2018-3970 | MEDIUM | 5.5 | 0.5% | Oct 25, 2018 | An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Al... |
| CVE-2018-18568 | MEDIUM | 5.9 | 0.7% | Oct 24, 2018 | Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credentia... |
| CVE-2018-18566 | MEDIUM | 5.3 | 2.8% | Oct 24, 2018 | The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive ph... |
| CVE-2018-18014 | MEDIUM | 4.8 | 0.5% | Oct 24, 2018 | * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now