2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15669 | — | — | 0.9% | Aug 21, 2018 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolic... |
| CVE-2018-15668 | — | — | 0.9% | Aug 21, 2018 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an ex... |
| CVE-2018-15667 | — | — | 1.0% | Aug 21, 2018 | An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" ... |
| CVE-2018-10902 | HIGH | 7.8 | 0.5% | Aug 21, 2018 | It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc ... |
| CVE-2018-10932 | MEDIUM | 4.3 | 1.0% | Aug 21, 2018 | lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is dis... |
| CVE-2018-15661 | — | — | 1.2% | Aug 21, 2018 | An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker contro... |
| CVE-2018-15660 | — | — | 1.2% | Aug 21, 2018 | An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker contro... |
| CVE-2018-6557 | HIGH | 7 | 0.4% | Aug 21, 2018 | The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1u... |
| CVE-2018-15534 | — | — | 32.4% | Aug 21, 2018 | Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information includin... |
| CVE-2018-15533 | — | — | 2.6% | Aug 21, 2018 | A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query... |
| CVE-2018-15528 | — | — | 1.3% | Aug 21, 2018 | Reflected Cross-Site Scripting exists in the Java System Solutions SSO plugin 4.0.13.1 for BMC MyIT. A remote attacker c... |
| CVE-2018-15481 | — | — | 1.3% | Aug 21, 2018 | Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices using firmwa... |
| CVE-2018-15607 | — | — | 5.1% | Aug 21, 2018 | In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1... |
| CVE-2018-6692 | CRITICAL | 10 | 3.7% | Aug 21, 2018 | Stack-based Buffer Overflow vulnerability in libUPnPHndlr.so in Belkin Wemo Insight Smart Plug allows remote attackers t... |
| CVE-2018-14795 | — | — | 2.2% | Aug 21, 2018 | DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an ... |
| CVE-2018-14793 | — | — | 1.0% | Aug 21, 2018 | DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable to a buffer overflow exploit through an open commun... |
| CVE-2018-7166 | HIGH | 7.5 | 3.2% | Aug 21, 2018 | In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitia... |
| CVE-2018-12115 | — | — | 8.0% | Aug 21, 2018 | In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under... |
| CVE-2018-15603 | — | — | 0.6% | Aug 21, 2018 | An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" scr... |
| CVE-2018-15601 | — | — | 1.6% | Aug 21, 2018 | apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload ... |
| CVE-2018-15599 | — | — | 2.7% | Aug 21, 2018 | The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerab... |
| CVE-2018-15598 | — | — | 2.9% | Aug 21, 2018 | Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is mis... |
| CVE-2018-0501 | — | — | 1.0% | Aug 21, 2018 | The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mish... |
| CVE-2018-14023 | — | — | 0.5% | Aug 20, 2018 | Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage. |
| CVE-2018-14020 | — | — | 1.1% | Aug 20, 2018 | An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker ca... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now