2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3909 | HIGH | 8.6 | 1.3% | Aug 24, 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET... |
| CVE-2018-15822 | HIGH | 7.5 | 3.3% | Aug 23, 2018 | The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, le... |
| CVE-2018-3911 | HIGH | 8.6 | 1.2% | Aug 23, 2018 | An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 -... |
| CVE-2018-14797 | HIGH | 7.8 | 1.7% | Aug 23, 2018 | Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the se... |
| CVE-2018-14791 | HIGH | 7.8 | 0.4% | Aug 23, 2018 | Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable a... |
| CVE-2018-3912 | HIGH | 7.8 | 0.4% | Aug 23, 2018 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts... |
| CVE-2018-3925 | HIGH | 8.5 | 1.5% | Aug 23, 2018 | An exploitable buffer overflow vulnerability exists in the remote video-host communication of video-core's HTTP server o... |
| CVE-2018-3879 | HIGH | 8.8 | 1.6% | Aug 23, 2018 | An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sma... |
| CVE-2018-3833 | HIGH | 7.5 | 1.1% | Aug 23, 2018 | An exploitable firmware downgrade vulnerability exists in Insteon Hub running firmware version 1013. The firmware upgrad... |
| CVE-2018-14787 | HIGH | 7.8 | 0.4% | Aug 22, 2018 | In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an... |
| CVE-2018-1139 | HIGH | 8.1 | 3.1% | Aug 22, 2018 | A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 ... |
| CVE-2018-10884 | HIGH | 8.8 | 0.9% | Aug 22, 2018 | Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authenticati... |
| CVE-2018-11776 | HIGH | 8.1 | 100.0% | Aug 22, 2018 | Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN... |
| CVE-2018-10902 | HIGH | 7.8 | 0.5% | Aug 21, 2018 | It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc ... |
| CVE-2018-6557 | HIGH | 7 | 0.4% | Aug 21, 2018 | The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1u... |
| CVE-2018-7166 | HIGH | 7.5 | 3.2% | Aug 21, 2018 | In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitia... |
| CVE-2018-1656 | HIGH | 7.4 | 4.5% | Aug 20, 2018 | The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , ... |
| CVE-2018-1000632 | HIGH | 7.5 | 6.6% | Aug 20, 2018 | dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addEleme... |
| CVE-2018-15573 | HIGH | 8.8 | 2.1% | Aug 20, 2018 | An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read an... |
| CVE-2018-15560 | HIGH | 7.5 | 1.7% | Aug 20, 2018 | PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and ... |
| CVE-2018-15505 | HIGH | 7.5 | 2.2% | Aug 18, 2018 | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially... |
| CVE-2018-15504 | HIGH | 7.5 | 2.8% | Aug 18, 2018 | An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP reque... |
| CVE-2018-15501 | HIGH | 7.5 | 4.3% | Aug 18, 2018 | In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a craf... |
| CVE-2018-15471 | HIGH | 7.8 | 0.4% | Aug 17, 2018 | An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1,... |
| CVE-2018-5546 | HIGH | 7.8 | 0.5% | Aug 17, 2018 | The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now