2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10923 | HIGH | 8.1 | 1.7% | Sep 4, 2018 | It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node... |
| CVE-2018-10911 | HIGH | 7.5 | 3.1% | Sep 4, 2018 | A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacke... |
| CVE-2018-10907 | HIGH | 8.8 | 3.4% | Sep 4, 2018 | It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc... |
| CVE-2018-10904 | HIGH | 8.8 | 3.0% | Sep 4, 2018 | It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribu... |
| CVE-2018-16384 | HIGH | 7.5 | 1.7% | Sep 3, 2018 | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0... |
| CVE-2018-11054 | HIGH | 7.5 | 3.2% | Aug 31, 2018 | RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use ma... |
| CVE-2018-3787 | HIGH | 7.5 | 2.0% | Aug 31, 2018 | Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server. |
| CVE-2018-16276 | HIGH | 7.8 | 0.4% | Aug 31, 2018 | An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers cou... |
| CVE-2018-7685 | HIGH | 7.8 | 0.3% | Aug 31, 2018 | The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the c... |
| CVE-2018-6499 | HIGH | 7.1 | 2.4% | Aug 30, 2018 | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2... |
| CVE-2018-6498 | HIGH | 8.8 | 3.1% | Aug 30, 2018 | Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2... |
| CVE-2018-13822 | HIGH | 7.5 | 1.3% | Aug 30, 2018 | Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, all... |
| CVE-2018-14622 | HIGH | 7.5 | 3.9% | Aug 30, 2018 | A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt... |
| CVE-2018-10936 | HIGH | 8.1 | 2.9% | Aug 30, 2018 | A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t... |
| CVE-2018-14619 | HIGH | 7.8 | 0.4% | Aug 30, 2018 | A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was bei... |
| CVE-2018-16057 | HIGH | 7.5 | 3.4% | Aug 30, 2018 | In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed... |
| CVE-2018-7792 | HIGH | 7.5 | 1.1% | Aug 29, 2018 | A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all ref... |
| CVE-2018-7789 | HIGH | 7.5 | 2.8% | Aug 29, 2018 | An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 produc... |
| CVE-2018-3916 | HIGH | 7.8 | 0.4% | Aug 28, 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT... |
| CVE-2018-3908 | HIGH | 7.5 | 1.3% | Aug 28, 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET... |
| CVE-2018-3895 | HIGH | 8.8 | 1.8% | Aug 28, 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa... |
| CVE-2018-3918 | HIGH | 7.5 | 1.0% | Aug 27, 2018 | An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20... |
| CVE-2018-3893 | HIGH | 8.8 | 1.8% | Aug 27, 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa... |
| CVE-2018-15877 | HIGH | 8.8 | 77.0% | Aug 26, 2018 | The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta... |
| CVE-2018-11654 | HIGH | 7.5 | 2.0% | Aug 24, 2018 | Information disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now