2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15610 | HIGH | 7.3 | 1.8% | Sep 12, 2018 | A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arb... |
| CVE-2018-3885 | HIGH | 8.8 | 0.9% | Sep 12, 2018 | An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re... |
| CVE-2018-3884 | HIGH | 8.8 | 0.9% | Sep 12, 2018 | An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re... |
| CVE-2018-3883 | HIGH | 8.8 | 0.9% | Sep 12, 2018 | An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re... |
| CVE-2018-3882 | HIGH | 8.8 | 0.9% | Sep 12, 2018 | An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re... |
| CVE-2018-10893 | HIGH | 7.6 | 2.4% | Sep 11, 2018 | Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames.... |
| CVE-2018-10853 | HIGH | 7 | 0.5% | Sep 11, 2018 | A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrst... |
| CVE-2018-1571 | HIGH | 8.8 | 4.7% | Sep 11, 2018 | IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sendi... |
| CVE-2018-3897 | HIGH | 8.8 | 1.5% | Sep 10, 2018 | An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of S... |
| CVE-2018-3896 | HIGH | 8.8 | 1.5% | Sep 10, 2018 | An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of S... |
| CVE-2018-15552 | HIGH | 7.5 | 1.2% | Sep 7, 2018 | The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling... |
| CVE-2018-4010 | HIGH | 7.8 | 4.7% | Sep 7, 2018 | An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A special... |
| CVE-2018-3952 | HIGH | 8.8 | 0.9% | Sep 7, 2018 | An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafte... |
| CVE-2018-1789 | HIGH | 8.4 | 1.2% | Sep 7, 2018 | IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a ser... |
| CVE-2018-1756 | HIGH | 7.5 | 10.6% | Sep 7, 2018 | IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker co... |
| CVE-2018-5391 | HIGH | 7.5 | 24.6% | Sep 6, 2018 | The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packet... |
| CVE-2018-1695 | HIGH | 7.3 | 2.2% | Sep 6, 2018 | IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to con... |
| CVE-2018-14632 | HIGH | 7.7 | 1.9% | Sep 6, 2018 | An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Contai... |
| CVE-2018-14624 | HIGH | 7.5 | 2.5% | Sep 6, 2018 | A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the ... |
| CVE-2018-16552 | HIGH | 8.8 | 0.6% | Sep 5, 2018 | MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs. |
| CVE-2018-14618 | HIGH | 7.5 | 10.8% | Sep 5, 2018 | curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl... |
| CVE-2018-10929 | HIGH | 8.8 | 3.3% | Sep 4, 2018 | A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw... |
| CVE-2018-10928 | HIGH | 8.8 | 2.7% | Sep 4, 2018 | A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to... |
| CVE-2018-10927 | HIGH | 8.1 | 2.8% | Sep 4, 2018 | A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw... |
| CVE-2018-10926 | HIGH | 8.8 | 2.6% | Sep 4, 2018 | A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now