2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0270 | — | — | 0.7% | May 17, 2018 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unaut... |
| CVE-2018-0268 | — | — | 5.4% | May 17, 2018 | A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an ... |
| CVE-2018-0222 | — | — | 3.8% | May 17, 2018 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to lo... |
| CVE-2018-1172 | — | — | 8.9% | May 16, 2018 | This vulnerability allows remote attackers to deny service on vulnerable installations of The Squid Software Foundation ... |
| CVE-2018-4850 | — | — | 2.5% | May 16, 2018 | A vulnerability has been identified in SIMATIC S7-400 (incl. F) CPU hardware version 4.0 and below (All versions), SIMAT... |
| CVE-2018-11214 | — | — | 2.4% | May 16, 2018 | An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denia... |
| CVE-2018-11213 | — | — | 2.6% | May 16, 2018 | An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a deni... |
| CVE-2018-11212 | — | — | 4.9% | May 16, 2018 | An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a ... |
| CVE-2018-8014 | — | — | 22.0% | May 16, 2018 | The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0... |
| CVE-2018-11210 | — | — | 2.1% | May 16, 2018 | TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml... |
| CVE-2018-11209 | — | — | 1.0% | May 16, 2018 | An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which... |
| CVE-2018-11208 | — | — | 0.9% | May 16, 2018 | An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary w... |
| CVE-2018-11207 | — | — | 2.2% | May 16, 2018 | A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remo... |
| CVE-2018-11206 | — | — | 2.9% | May 16, 2018 | An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 ... |
| CVE-2018-11205 | — | — | 2.4% | May 16, 2018 | A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote d... |
| CVE-2018-11204 | — | — | 1.7% | May 16, 2018 | A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It cou... |
| CVE-2018-11203 | — | — | 1.7% | May 16, 2018 | A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow ... |
| CVE-2018-11202 | — | — | 2.0% | May 16, 2018 | A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could... |
| CVE-2018-10760 | — | — | 1.2% | May 16, 2018 | Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated u... |
| CVE-2018-10241 | — | — | 1.7% | May 16, 2018 | A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the appl... |
| CVE-2018-10240 | — | — | 1.1% | May 16, 2018 | SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in... |
| CVE-2018-5231 | — | — | 2.8% | May 16, 2018 | The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from ve... |
| CVE-2018-10810 | — | — | 0.6% | May 16, 2018 | chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Langua... |
| CVE-2018-10738 | — | — | 42.6% | May 16, 2018 | A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter. |
| CVE-2018-10737 | — | — | 42.6% | May 16, 2018 | A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now