2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10655 | — | — | 15.6% | May 10, 2018 | DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH). |
| CVE-2018-9112 | — | — | 1.3% | May 10, 2018 | A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5... |
| CVE-2018-9111 | — | — | 0.5% | May 10, 2018 | Cross Site Scripting (XSS) exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via the configur... |
| CVE-2018-8824 | — | — | 1.4% | May 10, 2018 | modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for Pre... |
| CVE-2018-8061 | — | — | 0.4% | May 10, 2018 | HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device dri... |
| CVE-2018-8060 | — | — | 0.6% | May 10, 2018 | HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If ... |
| CVE-2018-10942 | — | — | 12.7% | May 10, 2018 | modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 a... |
| CVE-2018-10314 | — | — | 1.9% | May 10, 2018 | Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web s... |
| CVE-2018-10963 | — | — | 3.8% | May 10, 2018 | The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denia... |
| CVE-2018-10962 | — | — | 0.4% | May 10, 2018 | An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe, 2345SafeTray.exe, and 2345Speedup.exe al... |
| CVE-2018-10958 | — | — | 2.5% | May 10, 2018 | In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2... |
| CVE-2018-10957 | — | — | 0.9% | May 10, 2018 | CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidge... |
| CVE-2018-10955 | — | — | 0.4% | May 10, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10954 | — | — | 0.4% | May 10, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10953 | — | — | 0.4% | May 10, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10952 | — | — | 0.4% | May 10, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10950 | — | — | 1.4% | May 10, 2018 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows I... |
| CVE-2018-10949 | — | — | 2.4% | May 10, 2018 | mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by... |
| CVE-2018-8860 | — | — | 0.7% | May 9, 2018 | In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker may be able to capture firmware updates through the adjace... |
| CVE-2018-6021 | — | — | 1.3% | May 9, 2018 | Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call param... |
| CVE-2018-6020 | — | — | 1.1% | May 9, 2018 | In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when maki... |
| CVE-2018-2416 | — | — | 1.5% | May 9, 2018 | SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source. |
| CVE-2018-8866 | — | — | 2.2% | May 9, 2018 | In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection. |
| CVE-2018-8179 | — | — | 12.9% | May 9, 2018 | A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E... |
| CVE-2018-8178 | — | — | 14.2% | May 9, 2018 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now