2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1114 | MEDIUM | 6.5 | 2.3% | Sep 11, 2018 | It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized whi... |
| CVE-2018-10935 | MEDIUM | 6.5 | 1.8% | Sep 11, 2018 | A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with... |
| CVE-2018-10893 | HIGH | 7.6 | 2.4% | Sep 11, 2018 | Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames.... |
| CVE-2018-6976 | MEDIUM | 5.3 | 1.2% | Sep 11, 2018 | The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vu... |
| CVE-2018-6975 | — | — | 0.3% | Sep 11, 2018 | The AirWatch Agent for iOS prior to 5.8.1 contains a data protection vulnerability whereby the files and keychain entrie... |
| CVE-2018-10853 | HIGH | 7 | 0.5% | Sep 11, 2018 | A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrst... |
| CVE-2018-16832 | — | — | 0.6% | Sep 11, 2018 | CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because... |
| CVE-2018-16831 | — | — | 2.7% | Sep 11, 2018 | Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in... |
| CVE-2018-1571 | HIGH | 8.8 | 4.7% | Sep 11, 2018 | IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sendi... |
| CVE-2018-16807 | — | — | 1.4% | Sep 11, 2018 | In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Ke... |
| CVE-2018-16806 | — | — | 0.5% | Sep 10, 2018 | A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and possibly other vehicles, relie... |
| CVE-2018-16805 | — | — | 0.8% | Sep 10, 2018 | In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link... |
| CVE-2018-11775 | — | — | 7.0% | Sep 10, 2018 | TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vu... |
| CVE-2018-3875 | CRITICAL | 9.9 | 1.5% | Sep 10, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-14636 | MEDIUM | 5.3 | 1.2% | Sep 10, 2018 | Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief windo... |
| CVE-2018-14635 | MEDIUM | 6.5 | 2.5% | Sep 10, 2018 | When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an... |
| CVE-2018-14620 | MEDIUM | 4.7 | 0.6% | Sep 10, 2018 | The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build ... |
| CVE-2018-16705 | — | — | 1.6% | Sep 10, 2018 | FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the syst... |
| CVE-2018-16591 | — | — | 2.2% | Sep 10, 2018 | FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service acco... |
| CVE-2018-12608 | — | — | 0.9% | Sep 10, 2018 | An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both t... |
| CVE-2018-16802 | — | — | 2.2% | Sep 10, 2018 | An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running o... |
| CVE-2018-3897 | HIGH | 8.8 | 1.5% | Sep 10, 2018 | An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of S... |
| CVE-2018-3896 | HIGH | 8.8 | 1.5% | Sep 10, 2018 | An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of S... |
| CVE-2018-16797 | — | — | 2.7% | Sep 10, 2018 | A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary cod... |
| CVE-2018-16608 | — | — | 1.2% | Sep 10, 2018 | In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/ind... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now