2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12335 | — | — | 0.4% | Jun 17, 2018 | Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication... |
| CVE-2018-12334 | — | — | 0.6% | Jun 17, 2018 | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication a... |
| CVE-2018-12333 | — | — | 0.4% | Jun 17, 2018 | Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacke... |
| CVE-2018-12332 | — | — | 0.2% | Jun 17, 2018 | Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authenticati... |
| CVE-2018-12331 | — | — | 0.9% | Jun 17, 2018 | Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the... |
| CVE-2018-12330 | — | — | 0.8% | Jun 17, 2018 | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication a... |
| CVE-2018-12329 | — | — | 0.9% | Jun 17, 2018 | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentic... |
| CVE-2018-11647 | — | — | 0.9% | Jun 17, 2018 | index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL. |
| CVE-2018-10969 | — | — | 5.3% | Jun 17, 2018 | SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar... |
| CVE-2018-10377 | — | — | 0.9% | Jun 17, 2018 | PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which m... |
| CVE-2018-12326 | — | — | 2.7% | Jun 17, 2018 | Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution ... |
| CVE-2018-12262 | — | — | — | Jun 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-12454 | — | — | 1.3% | Jun 17, 2018 | The _addguess function of a simplelottery smart contract implementation for 1000 Guess, an Ethereum gambling game, gener... |
| CVE-2018-12453 | — | — | 24.2% | Jun 16, 2018 | Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers t... |
| CVE-2018-12504 | — | — | 1.6% | Jun 16, 2018 | tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h. |
| CVE-2018-12503 | — | — | 1.8% | Jun 16, 2018 | tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h. |
| CVE-2018-12501 | — | — | 1.7% | Jun 16, 2018 | Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335. |
| CVE-2018-9859 | — | — | 0.9% | Jun 16, 2018 | The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persist... |
| CVE-2018-5756 | — | — | 5.6% | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4... |
| CVE-2018-5755 | — | — | 8.0% | Jun 16, 2018 | Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.... |
| CVE-2018-5754 | — | — | 3.0% | Jun 16, 2018 | Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and... |
| CVE-2018-5753 | — | — | 8.4% | Jun 16, 2018 | The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev... |
| CVE-2018-5752 | — | — | 8.3% | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4... |
| CVE-2018-5751 | — | — | 9.2% | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4... |
| CVE-2018-11223 | — | — | 1.3% | Jun 16, 2018 | XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now