2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16460 | — | — | 2.9% | Sep 7, 2018 | A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker co... |
| CVE-2018-16704 | — | — | 0.8% | Sep 7, 2018 | An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possibl... |
| CVE-2018-16703 | — | — | 1.5% | Sep 7, 2018 | A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple us... |
| CVE-2018-16667 | — | — | 0.3% | Sep 7, 2018 | An issue was discovered in Contiki-NG through 4.1. There is a buffer over-read in lookup in os/storage/antelope/lvm.c wh... |
| CVE-2018-16666 | — | — | 0.3% | Sep 7, 2018 | An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in next_string in os/storage/a... |
| CVE-2018-16665 | — | — | 0.3% | Sep 7, 2018 | An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow while parsing AQL in lvm_shift_for_operato... |
| CVE-2018-16664 | — | — | 0.3% | Sep 7, 2018 | An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow in lvm_set_type in os/storage/antelope/lvm... |
| CVE-2018-16663 | — | — | 0.3% | Sep 7, 2018 | An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/stora... |
| CVE-2018-4010 | HIGH | 7.8 | 4.7% | Sep 7, 2018 | An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A special... |
| CVE-2018-3952 | HIGH | 8.8 | 0.9% | Sep 7, 2018 | An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafte... |
| CVE-2018-1789 | HIGH | 8.4 | 1.2% | Sep 7, 2018 | IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a ser... |
| CVE-2018-1757 | MEDIUM | 5.3 | 1.7% | Sep 7, 2018 | IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive informat... |
| CVE-2018-1756 | HIGH | 7.5 | 10.6% | Sep 7, 2018 | IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker co... |
| CVE-2018-1567 | CRITICAL | 9.8 | 4.2% | Sep 7, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code thro... |
| CVE-2018-16658 | — | — | 0.6% | Sep 7, 2018 | An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cd... |
| CVE-2018-16657 | — | — | 3.6% | Sep 7, 2018 | In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation ... |
| CVE-2018-0663 | — | — | 1.6% | Sep 7, 2018 | Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and ea... |
| CVE-2018-0662 | — | — | 0.4% | Sep 7, 2018 | Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and ea... |
| CVE-2018-0661 | — | — | 0.6% | Sep 7, 2018 | Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and ea... |
| CVE-2018-0660 | — | — | 1.2% | Sep 7, 2018 | Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create ar... |
| CVE-2018-0659 | — | — | 1.4% | Sep 7, 2018 | Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create or... |
| CVE-2018-0658 | — | — | 1.0% | Sep 7, 2018 | Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) versio... |
| CVE-2018-0657 | — | — | 0.5% | Sep 7, 2018 | Cross-site scripting vulnerability in EC-CUBE Payment Module and GMO-PG Payment Module (PG Multi-Payment Service) for EC... |
| CVE-2018-0655 | — | — | 0.7% | Sep 7, 2018 | Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra... |
| CVE-2018-0654 | — | — | 0.9% | Sep 7, 2018 | Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now