2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15839 | CRITICAL | 9.8 | 45.3% | Aug 28, 2018 | D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. |
| CVE-2018-15571 | — | — | 1.5% | Aug 28, 2018 | The Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection. |
| CVE-2018-15529 | — | — | 4.8% | Aug 28, 2018 | A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authentic... |
| CVE-2018-13395 | — | — | 1.0% | Aug 28, 2018 | Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 be... |
| CVE-2018-13391 | — | — | 1.8% | Aug 28, 2018 | The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from v... |
| CVE-2018-1705 | MEDIUM | 6.5 | 1.3% | Aug 28, 2018 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclo... |
| CVE-2018-15919 | MEDIUM | 5.3 | 3.6% | Aug 28, 2018 | Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existenc... |
| CVE-2018-15911 | — | — | 3.0% | Aug 28, 2018 | In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memor... |
| CVE-2018-3690 | — | — | — | Aug 27, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3693. Reason: This issue was MERGED into CVE-201... |
| CVE-2018-15910 | — | — | 3.0% | Aug 27, 2018 | In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the ... |
| CVE-2018-15909 | — | — | 3.0% | Aug 27, 2018 | In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers ab... |
| CVE-2018-15908 | — | — | 1.9% | Aug 27, 2018 | In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfi... |
| CVE-2018-3927 | MEDIUM | 6.8 | 1.1% | Aug 27, 2018 | An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung Sma... |
| CVE-2018-3918 | HIGH | 7.5 | 1.0% | Aug 27, 2018 | An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20... |
| CVE-2018-3904 | CRITICAL | 9.9 | 1.8% | Aug 27, 2018 | An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsun... |
| CVE-2018-3893 | HIGH | 8.8 | 1.8% | Aug 27, 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa... |
| CVE-2018-15904 | — | — | 1.1% | Aug 27, 2018 | A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8,... |
| CVE-2018-15887 | — | — | 3.7% | Aug 27, 2018 | Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allo... |
| CVE-2018-15810 | — | — | 1.8% | Aug 27, 2018 | Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize f... |
| CVE-2018-1644 | LOW | 3.1 | 0.9% | Aug 27, 2018 | IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 -... |
| CVE-2018-15699 | — | — | 0.6% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in t... |
| CVE-2018-15698 | — | — | 1.1% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file sy... |
| CVE-2018-15697 | — | — | 0.9% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by ... |
| CVE-2018-15696 | — | — | 0.7% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts ... |
| CVE-2018-15695 | — | — | 1.0% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now