2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10746 | — | — | 2.7% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' para... |
| CVE-2018-10740 | — | — | 2.8% | May 4, 2018 | Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parame... |
| CVE-2018-9063 | — | — | 0.4% | May 4, 2018 | MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contai... |
| CVE-2018-8872 | — | — | 2.3% | May 4, 2018 | In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory ... |
| CVE-2018-8869 | — | — | 2.3% | May 4, 2018 | In Lantech IDS 2102 2.0 and prior, nearly all input fields allow for arbitrary input on the device. A CVSS v3 base score... |
| CVE-2018-8861 | — | — | 0.4% | May 4, 2018 | Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iC... |
| CVE-2018-8857 | — | — | 0.3% | May 4, 2018 | Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillanc... |
| CVE-2018-8853 | — | — | 0.4% | May 4, 2018 | Philips Brilliance CT devices operate user functions from within a contained kiosk in a Microsoft Windows operating syst... |
| CVE-2018-7522 | — | — | 0.4% | May 4, 2018 | In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers a... |
| CVE-2018-10739 | — | — | 0.4% | May 4, 2018 | An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe allows local users to bypass intended pro... |
| CVE-2018-10733 | — | — | 2.3% | May 4, 2018 | There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A cra... |
| CVE-2018-10641 | — | — | 1.8% | May 4, 2018 | D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext. |
| CVE-2018-10722 | — | — | 0.5% | May 4, 2018 | In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify... |
| CVE-2018-8003 | — | — | 4.5% | May 3, 2018 | Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user ... |
| CVE-2018-10718 | — | — | 31.6% | May 3, 2018 | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote at... |
| CVE-2018-10168 | — | — | 1.6% | May 3, 2018 | TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of ... |
| CVE-2018-10167 | — | — | 1.2% | May 3, 2018 | The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows ... |
| CVE-2018-10166 | — | — | 0.7% | May 3, 2018 | The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows doe... |
| CVE-2018-10165 | — | — | 0.6% | May 3, 2018 | Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Window... |
| CVE-2018-10164 | — | — | 0.6% | May 3, 2018 | Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Window... |
| CVE-2018-10717 | — | — | 2.0% | May 3, 2018 | The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure... |
| CVE-2018-10716 | — | — | 0.4% | May 3, 2018 | An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe, 2345SafeTray.exe, and 2345Speedup.exe al... |
| CVE-2018-10713 | — | — | 2.4% | May 3, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' par... |
| CVE-2018-4849 | — | — | 0.8% | May 3, 2018 | A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance ... |
| CVE-2018-10689 | — | — | 2.0% | May 3, 2018 | blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_r... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now