2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0027 | HIGH | 7.5 | 2.4% | Jul 11, 2018 | Receipt of a crafted or malformed RSVP PATH message may cause the routing protocol daemon (RPD) to hang or crash. When R... |
| CVE-2018-0026 | MEDIUM | 4.7 | 1.8% | Jul 11, 2018 | After Junos OS device reboot or upgrade, the stateless firewall filter configuration may not take effect. This issue can... |
| CVE-2018-0025 | MEDIUM | 6.1 | 1.4% | Jul 11, 2018 | When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authent... |
| CVE-2018-0024 | HIGH | 7.8 | 0.4% | Jul 11, 2018 | An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated u... |
| CVE-2018-10635 | — | — | 5.1% | Jul 11, 2018 | In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbi... |
| CVE-2018-10633 | — | — | 1.8% | Jul 11, 2018 | Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow a... |
| CVE-2018-10232 | MEDIUM | 6.5 | 0.6% | Jul 11, 2018 | Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows... |
| CVE-2018-10231 | — | — | 0.8% | Jul 11, 2018 | Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote... |
| CVE-2018-3936 | HIGH | 8.8 | 2.0% | Jul 11, 2018 | In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft ... |
| CVE-2018-3933 | HIGH | 8.8 | 2.1% | Jul 11, 2018 | An exploitable out-of-bounds write exists in the Microsoft Word document conversion functionality of the Antenna House O... |
| CVE-2018-3932 | HIGH | 8.8 | 2.5% | Jul 11, 2018 | An exploitable stack-based buffer overflow exists in the Microsoft Word document conversion functionality of the Antenna... |
| CVE-2018-3931 | HIGH | 7.8 | 2.5% | Jul 11, 2018 | In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft ... |
| CVE-2018-3930 | HIGH | 7.8 | 1.6% | Jul 11, 2018 | In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft ... |
| CVE-2018-3929 | HIGH | 7.8 | 2.5% | Jul 11, 2018 | An exploitable heap corruption exists in the PowerPoint document conversion functionality of the Antenna House Office Se... |
| CVE-2018-13989 | — | — | 3.2% | Jul 11, 2018 | Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable... |
| CVE-2018-11529 | — | — | 40.6% | Jul 11, 2018 | VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arb... |
| CVE-2018-10197 | — | — | 1.5% | Jul 11, 2018 | There is a time-based blind SQL injection vulnerability in the Access Manager component before 9.18.040 and 10.x before ... |
| CVE-2018-8007 | — | — | 11.7% | Jul 11, 2018 | Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of adm... |
| CVE-2018-0500 | — | — | 6.4% | Jul 11, 2018 | Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that mig... |
| CVE-2018-13879 | — | — | 0.6% | Jul 11, 2018 | A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, t... |
| CVE-2018-13878 | — | — | 0.8% | Jul 11, 2018 | An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a u... |
| CVE-2018-8356 | — | — | 0.7% | Jul 11, 2018 | A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certif... |
| CVE-2018-8327 | CRITICAL | 9.8 | 21.2% | Jul 11, 2018 | A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code ... |
| CVE-2018-8326 | — | — | 2.4% | Jul 11, 2018 | A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Feder... |
| CVE-2018-8325 | — | — | 5.7% | Jul 11, 2018 | An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now