2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10840 | MEDIUM | 6.6 | 0.7% | Jul 16, 2018 | Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An at... |
| CVE-2018-1046 | HIGH | 7.8 | 1.4% | Jul 16, 2018 | pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS ... |
| CVE-2018-10886 | — | — | — | Jul 16, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate is not about any specific ... |
| CVE-2018-14326 | — | — | 1.9% | Jul 16, 2018 | In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom... |
| CVE-2018-14325 | — | — | 2.0% | Jul 16, 2018 | In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp. |
| CVE-2018-14324 | — | — | 4.4% | Jul 16, 2018 | The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin ... |
| CVE-2018-10859 | MEDIUM | 5.9 | 1.4% | Jul 16, 2018 | git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could ... |
| CVE-2018-5239 | — | — | 0.4% | Jul 16, 2018 | Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit. In this type of circumstance, the exploit ca... |
| CVE-2018-0385 | HIGH | 7.5 | 2.3% | Jul 16, 2018 | A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower Syst... |
| CVE-2018-0384 | — | — | 2.5% | Jul 16, 2018 | A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attack... |
| CVE-2018-0383 | — | — | 3.0% | Jul 16, 2018 | A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attack... |
| CVE-2018-0370 | — | — | 2.2% | Jul 16, 2018 | A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack... |
| CVE-2018-0369 | — | — | 2.3% | Jul 16, 2018 | A vulnerability in the reassembly logic for fragmented IPv4 packets of Cisco StarOS running on virtual platforms could a... |
| CVE-2018-0368 | — | — | 0.3% | Jul 16, 2018 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to acces... |
| CVE-2018-0366 | — | — | 1.8% | Jul 16, 2018 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticat... |
| CVE-2018-0361 | — | — | 1.6% | Jul 16, 2018 | ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively smal... |
| CVE-2018-0360 | — | — | 1.7% | Jul 16, 2018 | ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor fil... |
| CVE-2018-0341 | — | — | 5.9% | Jul 16, 2018 | A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.... |
| CVE-2018-13981 | — | — | 17.3% | Jul 16, 2018 | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code ... |
| CVE-2018-13980 | MEDIUM | 5.5 | 6.9% | Jul 16, 2018 | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos... |
| CVE-2018-11717 | — | — | 8.6% | Jul 16, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a contex... |
| CVE-2018-11716 | — | — | 14.3% | Jul 16, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to al... |
| CVE-2018-5229 | — | — | 0.6% | Jul 16, 2018 | The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remot... |
| CVE-2018-14071 | — | — | 3.1% | Jul 16, 2018 | The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input. |
| CVE-2018-13387 | — | — | 1.5% | Jul 16, 2018 | The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5,... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now