2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15535 | — | — | 45.2% | Aug 24, 2018 | /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname ... |
| CVE-2018-15499 | — | — | 0.4% | Aug 24, 2018 | GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condi... |
| CVE-2018-15120 | MEDIUM | 6.5 | 11.5% | Aug 24, 2018 | libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denia... |
| CVE-2018-14600 | — | — | 9.7% | Aug 24, 2018 | An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as sign... |
| CVE-2018-14599 | CRITICAL | 9.8 | 5.0% | Aug 24, 2018 | An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-on... |
| CVE-2018-14598 | — | — | 4.8% | Aug 24, 2018 | An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in ... |
| CVE-2018-11065 | LOW | 2.7 | 1.3% | Aug 24, 2018 | The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x pr... |
| CVE-2018-11061 | CRITICAL | 9.1 | 5.0% | Aug 24, 2018 | RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to... |
| CVE-2018-11749 | — | — | 0.8% | Aug 24, 2018 | When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext t... |
| CVE-2018-1755 | MEDIUM | 5.9 | 3.5% | Aug 24, 2018 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorr... |
| CVE-2018-1722 | CRITICAL | 10 | 9.0% | Aug 24, 2018 | IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control... |
| CVE-2018-1699 | MEDIUM | 6.3 | 1.7% | Aug 24, 2018 | IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-cra... |
| CVE-2018-3909 | HIGH | 8.6 | 1.3% | Aug 24, 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET... |
| CVE-2018-3907 | CRITICAL | 10 | 1.4% | Aug 24, 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET... |
| CVE-2018-15822 | HIGH | 7.5 | 3.3% | Aug 23, 2018 | The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, le... |
| CVE-2018-3911 | HIGH | 8.6 | 1.2% | Aug 23, 2018 | An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 -... |
| CVE-2018-3880 | CRITICAL | 9.9 | 1.2% | Aug 23, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of vide... |
| CVE-2018-3872 | CRITICAL | 9.9 | 1.8% | Aug 23, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-3866 | CRITICAL | 9.9 | 1.5% | Aug 23, 2018 | An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsun... |
| CVE-2018-3856 | CRITICAL | 9.9 | 3.4% | Aug 23, 2018 | An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 -... |
| CVE-2018-15809 | — | — | 0.2% | Aug 23, 2018 | AccuPOS 2017.8 is installed with the insecure "Authenticated Users: Modify" permission for files within the installation... |
| CVE-2018-15808 | — | — | 2.3% | Aug 23, 2018 | POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM... |
| CVE-2018-15807 | — | — | 0.3% | Aug 23, 2018 | POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's... |
| CVE-2018-6558 | — | — | 0.6% | Aug 23, 2018 | The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values... |
| CVE-2018-14797 | HIGH | 7.8 | 1.7% | Aug 23, 2018 | Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the se... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now