2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1710 | HIGH | 8.4 | 0.5% | Sep 21, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffe... |
| CVE-2018-14645 | HIGH | 7.5 | 3.0% | Sep 21, 2018 | A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read acc... |
| CVE-2018-6505 | HIGH | 7.5 | 2.5% | Sep 20, 2018 | A potential Unauthenticated File Download vulnerability has been identified in ArcSight Management Center (ArcMC) in all... |
| CVE-2018-6504 | HIGH | 8.8 | 0.6% | Sep 20, 2018 | A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in... |
| CVE-2018-6500 | HIGH | 7.5 | 4.0% | Sep 20, 2018 | A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all ... |
| CVE-2018-3865 | HIGH | 8.8 | 1.8% | Sep 20, 2018 | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsu... |
| CVE-2018-3864 | HIGH | 8.8 | 1.8% | Sep 20, 2018 | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsu... |
| CVE-2018-3831 | HIGH | 8.8 | 2.0% | Sep 19, 2018 | Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secre... |
| CVE-2018-3827 | HIGH | 8.1 | 1.0% | Sep 19, 2018 | A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) pl... |
| CVE-2018-17182 | HIGH | 7.8 | 3.2% | Sep 19, 2018 | An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles ... |
| CVE-2018-17144 | HIGH | 7.5 | 6.7% | Sep 19, 2018 | Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.... |
| CVE-2018-6690 | HIGH | 7.1 | 0.3% | Sep 18, 2018 | Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and ... |
| CVE-2018-13982 | HIGH | 7.5 | 3.5% | Sep 18, 2018 | Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insuff... |
| CVE-2018-11071 | HIGH | 7.5 | 1.8% | Sep 18, 2018 | Dell EMC Isilon OneFS versions 7.1.1.x, 7.2.1.x, 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 and Dell EMC IsilonS... |
| CVE-2018-14631 | HIGH | 8.8 | 1.8% | Sep 17, 2018 | moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently fil... |
| CVE-2018-14630 | HIGH | 8.8 | 4.4% | Sep 17, 2018 | moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional re... |
| CVE-2018-1223 | HIGH | 8.8 | 0.9% | Sep 17, 2018 | Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to applic... |
| CVE-2018-17143 | HIGH | 7.5 | 2.8% | Sep 17, 2018 | The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a ... |
| CVE-2018-17142 | HIGH | 7.5 | 2.8% | Sep 17, 2018 | The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "pani... |
| CVE-2018-17095 | HIGH | 8.8 | 4.7% | Sep 16, 2018 | An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3... |
| CVE-2018-17075 | HIGH | 7.5 | 2.8% | Sep 16, 2018 | The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: ... |
| CVE-2018-14638 | HIGH | 7.5 | 2.6% | Sep 14, 2018 | A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function ... |
| CVE-2018-8440 | HIGH | 7.8 | 18.5% | Sep 13, 2018 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A... |
| CVE-2018-8409 | HIGH | 7.5 | 6.6% | Sep 13, 2018 | A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines ... |
| CVE-2018-16981 | HIGH | 8.8 | 1.6% | Sep 12, 2018 | stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__o... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now