2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15748 | — | — | 1.1% | Aug 23, 2018 | On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware ... |
| CVE-2018-3833 | HIGH | 7.5 | 1.1% | Aug 23, 2018 | An exploitable firmware downgrade vulnerability exists in Insteon Hub running firmware version 1013. The firmware upgrad... |
| CVE-2018-3832 | CRITICAL | 9 | 1.7% | Aug 23, 2018 | An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows... |
| CVE-2018-15685 | — | — | 10.4% | Aug 23, 2018 | GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindow... |
| CVE-2018-11758 | — | — | 3.0% | Aug 22, 2018 | This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler... |
| CVE-2018-14801 | — | — | 0.4% | Aug 22, 2018 | In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both t... |
| CVE-2018-14799 | — | — | 0.5% | Aug 22, 2018 | In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device d... |
| CVE-2018-14789 | MEDIUM | 6.7 | 0.4% | Aug 22, 2018 | In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an... |
| CVE-2018-14787 | HIGH | 7.8 | 0.4% | Aug 22, 2018 | In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an... |
| CVE-2018-5238 | — | — | 1.6% | Aug 22, 2018 | Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerabil... |
| CVE-2018-5235 | — | — | 0.4% | Aug 22, 2018 | Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue tha... |
| CVE-2018-10919 | MEDIUM | 4.3 | 2.2% | Aug 22, 2018 | The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access contro... |
| CVE-2018-10918 | MEDIUM | 5.2 | 2.5% | Aug 22, 2018 | A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An auth... |
| CVE-2018-10858 | MEDIUM | 4.3 | 4.3% | Aug 22, 2018 | A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malici... |
| CVE-2018-1140 | MEDIUM | 6.5 | 10.8% | Aug 22, 2018 | A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker ... |
| CVE-2018-1139 | HIGH | 8.1 | 3.1% | Aug 22, 2018 | A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 ... |
| CVE-2018-10884 | HIGH | 8.8 | 0.9% | Aug 22, 2018 | Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authenticati... |
| CVE-2018-11776 | HIGH | 8.1 | 100.0% | Aug 22, 2018 | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN... |
| CVE-2018-10846 | MEDIUM | 5.6 | 0.4% | Aug 22, 2018 | A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was fou... |
| CVE-2018-10845 | MEDIUM | 5.9 | 3.6% | Aug 22, 2018 | It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote atta... |
| CVE-2018-10844 | MEDIUM | 5.9 | 3.6% | Aug 22, 2018 | It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote atta... |
| CVE-2018-1599 | MEDIUM | 5.4 | 0.8% | Aug 22, 2018 | IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By pe... |
| CVE-2018-15672 | — | — | — | Aug 21, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11207. Reason: This candidate is a reservation ... |
| CVE-2018-15671 | — | — | 1.1% | Aug 21, 2018 | An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5... |
| CVE-2018-15670 | — | — | 0.7% | Aug 21, 2018 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolic... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now