2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16151 | HIGH | 7.5 | 1.9% | Sep 26, 2018 | In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the R... |
| CVE-2018-17555 | HIGH | 7.5 | 2.0% | Sep 26, 2018 | The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /s... |
| CVE-2018-8848 | HIGH | 7.5 | 2.0% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permi... |
| CVE-2018-10606 | HIGH | 8.8 | 1.9% | Sep 26, 2018 | WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple heap-based buffer overflow vulnerabilities that can be exploit... |
| CVE-2018-10602 | HIGH | 8.8 | 1.9% | Sep 26, 2018 | WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple stack-based buffer overflow vulnerabilities that can be exploi... |
| CVE-2018-1785 | HIGH | 7.5 | 1.1% | Sep 26, 2018 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that co... |
| CVE-2018-1545 | HIGH | 7.5 | 1.0% | Sep 26, 2018 | IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that co... |
| CVE-2018-14634 | HIGH | 7.8 | 14.8% | Sep 25, 2018 | An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a... |
| CVE-2018-1669 | HIGH | 7.1 | 1.9% | Sep 25, 2018 | IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15... |
| CVE-2018-1607 | HIGH | 7.1 | 1.9% | Sep 25, 2018 | IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity... |
| CVE-2018-1588 | HIGH | 7.1 | 1.9% | Sep 25, 2018 | IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to... |
| CVE-2018-15964 | HIGH | 7.5 | 7.9% | Sep 25, 2018 | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use ... |
| CVE-2018-14647 | HIGH | 7.5 | 10.9% | Sep 25, 2018 | Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy... |
| CVE-2018-14633 | HIGH | 7 | 8.7% | Sep 25, 2018 | A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a wa... |
| CVE-2018-6700 | HIGH | 7.8 | 0.9% | Sep 24, 2018 | DLL Search Order Hijacking vulnerability in Microsoft Windows Client in McAfee True Key (TK) before 5.1.165 allows local... |
| CVE-2018-15615 | HIGH | 7.2 | 0.3% | Sep 24, 2018 | A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract ... |
| CVE-2018-15613 | HIGH | 8.3 | 0.8% | Sep 21, 2018 | A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could re... |
| CVE-2018-15612 | HIGH | 8.3 | 0.4% | Sep 21, 2018 | A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add... |
| CVE-2018-14730 | HIGH | 7.5 | 1.7% | Sep 21, 2018 | An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests i... |
| CVE-2018-3915 | HIGH | 8.2 | 0.4% | Sep 21, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT... |
| CVE-2018-3914 | HIGH | 7.8 | 0.4% | Sep 21, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT... |
| CVE-2018-3906 | HIGH | 8.2 | 0.4% | Sep 21, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTT... |
| CVE-2018-3894 | HIGH | 8.8 | 1.8% | Sep 21, 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa... |
| CVE-2018-3876 | HIGH | 8.8 | 1.9% | Sep 21, 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm... |
| CVE-2018-1711 | HIGH | 8.4 | 0.4% | Sep 21, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now