2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25017 | CRITICAL | 9.8 | 1.7% | Jul 1, 2021 | RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable. |
| CVE-2018-25016 | CRITICAL | 9.8 | 1.3% | Jun 21, 2021 | Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection. |
| CVE-2018-10867 | CRITICAL | 9.1 | 1.1% | May 26, 2021 | Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an a... |
| CVE-2018-10866 | CRITICAL | 9.1 | 1.0% | May 26, 2021 | It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it ... |
| CVE-2018-25014 | CRITICAL | 9.8 | 2.2% | May 21, 2021 | A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). |
| CVE-2018-25013 | CRITICAL | 9.1 | 2.1% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). |
| CVE-2018-25012 | CRITICAL | 9.1 | 2.1% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). |
| CVE-2018-25011 | CRITICAL | 9.8 | 2.5% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). |
| CVE-2018-25010 | CRITICAL | 9.1 | 2.2% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). |
| CVE-2018-25009 | CRITICAL | 9.1 | 2.1% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). |
| CVE-2018-19945 | CRITICAL | 9.1 | 1.1% | Dec 31, 2020 | A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitati... |
| CVE-2018-14067 | CRITICAL | 9.8 | 7.0% | Dec 31, 2020 | Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command executio... |
| CVE-2018-15632 | CRITICAL | 9.1 | 1.2% | Dec 22, 2020 | Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and ear... |
| CVE-2018-19025 | CRITICAL | 9.8 | 1.5% | Nov 2, 2020 | In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on... |
| CVE-2018-17932 | CRITICAL | 9.8 | 1.5% | Nov 2, 2020 | JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and c... |
| CVE-2018-19950 | CRITICAL | 9.8 | 2.0% | Nov 2, 2020 | If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issu... |
| CVE-2018-19949 | CRITICAL | 9.8 | 24.4% | Oct 28, 2020 | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has alre... |
| CVE-2018-4296 | CRITICAL | 9.8 | 1.0% | Oct 27, 2020 | This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was addressed with addit... |
| CVE-2018-5353 | CRITICAL | 9.8 | 8.1% | Sep 30, 2020 | The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execu... |
| CVE-2018-20432 | CRITICAL | 9.8 | 3.9% | Sep 14, 2020 | D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows u... |
| CVE-2018-6446 | CRITICAL | 9.8 | 1.3% | Jun 29, 2020 | A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log ... |
| CVE-2018-21268 | CRITICAL | 9.8 | 4.3% | Jun 25, 2020 | The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host para... |
| CVE-2018-21251 | CRITICAL | 9.8 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name w... |
| CVE-2018-21246 | CRITICAL | 9.8 | 2.7% | Jun 15, 2020 | Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lac... |
| CVE-2018-21245 | CRITICAL | 9.1 | 1.1% | Jun 15, 2020 | Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now