2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6622 | — | — | 0.5% | Aug 17, 2018 | An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an ob... |
| CVE-2018-15471 | HIGH | 7.8 | 0.4% | Aug 17, 2018 | An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1,... |
| CVE-2018-15470 | — | — | 0.4% | Aug 17, 2018 | An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of eval... |
| CVE-2018-15469 | — | — | 0.4% | Aug 17, 2018 | An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor o... |
| CVE-2018-15468 | — | — | 0.3% | Aug 17, 2018 | An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtu... |
| CVE-2018-14058 | — | — | 28.9% | Aug 17, 2018 | Pimcore before 5.3.0 allows SQL Injection via the REST web service API. |
| CVE-2018-14057 | — | — | 3.3% | Aug 17, 2018 | Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati... |
| CVE-2018-1236 | — | — | — | Aug 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-11085 | — | — | — | Aug 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-15360 | — | — | 1.6% | Aug 17, 2018 | An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware ver... |
| CVE-2018-15359 | — | — | 1.6% | Aug 17, 2018 | An authenticated attacker with low privileges can use insecure sudo configuration to expand attack surface in Eltex ESP-... |
| CVE-2018-15358 | — | — | 1.3% | Aug 17, 2018 | An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in E... |
| CVE-2018-15357 | — | — | 1.1% | Aug 17, 2018 | An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmw... |
| CVE-2018-15356 | — | — | 2.5% | Aug 17, 2018 | An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0. |
| CVE-2018-8261 | — | — | — | Aug 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d... |
| CVE-2018-15355 | — | — | 0.8% | Aug 17, 2018 | Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware 3.5.30.1118. |
| CVE-2018-15354 | — | — | 2.1% | Aug 17, 2018 | A Buffer Overflow exploited through web interface by remote attacker can cause denial of service in Kraftway 24F2XG Rout... |
| CVE-2018-15353 | — | — | 7.7% | Aug 17, 2018 | A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG ... |
| CVE-2018-15352 | — | — | 1.4% | Aug 17, 2018 | An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118. |
| CVE-2018-15351 | — | — | 2.0% | Aug 17, 2018 | Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftwa... |
| CVE-2018-15350 | — | — | 4.7% | Aug 17, 2018 | Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileg... |
| CVE-2018-3785 | CRITICAL | 9.8 | 4.0% | Aug 17, 2018 | A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter. |
| CVE-2018-3784 | CRITICAL | 9.8 | 3.3% | Aug 17, 2018 | A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserial... |
| CVE-2018-3783 | — | — | 3.8% | Aug 17, 2018 | A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in ... |
| CVE-2018-5547 | — | — | 0.3% | Aug 17, 2018 | Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy lo... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now