2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16232 | HIGH | 8.8 | 7.8% | Oct 17, 2018 | An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. Th... |
| CVE-2018-10823 | HIGH | 8.8 | 78.2% | Oct 17, 2018 | An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02... |
| CVE-2018-10822 | HIGH | 7.5 | 40.1% | Oct 17, 2018 | Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L t... |
| CVE-2018-18436 | HIGH | 8.8 | 0.5% | Oct 17, 2018 | JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI. |
| CVE-2018-3955 | HIGH | 7.2 | 4.8% | Oct 17, 2018 | An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware ... |
| CVE-2018-3954 | HIGH | 7.2 | 3.4% | Oct 17, 2018 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version... |
| CVE-2018-3953 | HIGH | 7.2 | 13.3% | Oct 17, 2018 | Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version... |
| CVE-2018-17911 | HIGH | 7.8 | 3.2% | Oct 17, 2018 | LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remo... |
| CVE-2018-3209 | HIGH | 8.3 | 2.7% | Oct 17, 2018 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). The supported version that is affected ... |
| CVE-2018-3169 | HIGH | 8.3 | 4.0% | Oct 17, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions t... |
| CVE-2018-3149 | HIGH | 8.3 | 7.2% | Oct 17, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported vers... |
| CVE-2018-6974 | HIGH | 8.8 | 0.5% | Oct 16, 2018 | VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Wor... |
| CVE-2018-1747 | HIGH | 7.1 | 1.9% | Oct 15, 2018 | IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack ... |
| CVE-2018-1744 | HIGH | 7.7 | 2.6% | Oct 15, 2018 | IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the s... |
| CVE-2018-8890 | HIGH | 7.5 | 1.1% | Oct 12, 2018 | An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an att... |
| CVE-2018-1844 | HIGH | 7.1 | 1.9% | Oct 12, 2018 | IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processin... |
| CVE-2018-18225 | HIGH | 7.5 | 2.9% | Oct 12, 2018 | In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensu... |
| CVE-2018-17929 | HIGH | 7.8 | 1.8% | Oct 11, 2018 | In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerab... |
| CVE-2018-1745 | HIGH | 7.5 | 3.9% | Oct 11, 2018 | IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to mis... |
| CVE-2018-1738 | HIGH | 7.1 | 1.1% | Oct 11, 2018 | IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive informatio... |
| CVE-2018-0052 | HIGH | 7.2 | 4.9% | Oct 10, 2018 | If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can o... |
| CVE-2018-0051 | HIGH | 7.5 | 1.6% | Oct 10, 2018 | A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allow... |
| CVE-2018-0050 | HIGH | 7.5 | 2.3% | Oct 10, 2018 | An error handling vulnerability in Routing Protocols Daemon (RPD) of Juniper Networks Junos OS allows an attacker to cau... |
| CVE-2018-0049 | HIGH | 7.5 | 2.2% | Oct 10, 2018 | A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to... |
| CVE-2018-0048 | HIGH | 7.5 | 2.9% | Oct 10, 2018 | A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network b... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now