2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10294 | — | — | 0.7% | May 2, 2018 | Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS. |
| CVE-2018-10115 | — | — | 4.7% | May 2, 2018 | Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memor... |
| CVE-2018-8115 | — | — | 32.5% | May 2, 2018 | A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to prope... |
| CVE-2018-1104 | — | — | 2.5% | May 2, 2018 | Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job... |
| CVE-2018-10680 | — | — | 0.9% | May 2, 2018 | Z-BlogPHP 1.5.2 has a stored Cross Site Scripting Vulnerability exploitable by an administrator who navigates to "Web si... |
| CVE-2018-10677 | — | — | 2.0% | May 2, 2018 | The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allo... |
| CVE-2018-1101 | — | — | 2.0% | May 2, 2018 | Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows fo... |
| CVE-2018-10676 | — | — | 2.1% | May 2, 2018 | CeNova, Night OWL, Novo, Pulnix, QSee, Securus, and TBK Vision DVR devices allow remote attackers to download a file and... |
| CVE-2018-10665 | — | — | 1.2% | May 2, 2018 | ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files. |
| CVE-2018-10657 | — | — | 1.5% | May 2, 2018 | Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 ... |
| CVE-2018-9302 | — | — | 10.8% | May 2, 2018 | SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r... |
| CVE-2018-5520 | — | — | 1.1% | May 2, 2018 | On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell... |
| CVE-2018-5519 | — | — | 1.1% | May 2, 2018 | On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.3, or 11.2.1-11.6.3.1, administrative users by way of undisclosed methods ca... |
| CVE-2018-5518 | — | — | 0.4% | May 2, 2018 | On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest can cause a disruption... |
| CVE-2018-5517 | — | — | 1.8% | May 2, 2018 | On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an in... |
| CVE-2018-5516 | — | — | 0.3% | May 2, 2018 | On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.2, or 11.2.1-11.6.3.1, Enterprise Manager 3.1.1, BIG-IQ Centralized Management... |
| CVE-2018-5515 | — | — | 3.4% | May 2, 2018 | On F5 BIG-IP 13.0.0-13.1.0.5, using RADIUS authentication responses from a RADIUS server with IPv6 addresses may cause T... |
| CVE-2018-5514 | — | — | 4.0% | May 2, 2018 | On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data pla... |
| CVE-2018-5512 | — | — | 3.1% | May 2, 2018 | On F5 BIG-IP 13.1.0-13.1.0.5, when Large Receive Offload (LRO) and SYN cookies are enabled (default settings), undisclos... |
| CVE-2018-1468 | — | — | 1.0% | May 2, 2018 | IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sensitive API details t... |
| CVE-2018-6401 | — | — | 1.2% | May 2, 2018 | Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a ... |
| CVE-2018-10647 | — | — | 0.4% | May 2, 2018 | SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. T... |
| CVE-2018-10646 | — | — | 0.4% | May 2, 2018 | CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" serv... |
| CVE-2018-10645 | — | — | 0.4% | May 2, 2018 | Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVP... |
| CVE-2018-10642 | — | — | 7.5% | May 2, 2018 | Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now