2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10873 | HIGH | 8.3 | 3.9% | Aug 17, 2018 | A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages l... |
| CVE-2018-1712 | HIGH | 8.6 | 0.7% | Aug 16, 2018 | IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, us... |
| CVE-2018-0427 | HIGH | 8.8 | 6.1% | Aug 15, 2018 | A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authentic... |
| CVE-2018-0418 | HIGH | 8.6 | 4.0% | Aug 15, 2018 | A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services ... |
| CVE-2018-0409 | HIGH | 7.5 | 3.5% | Aug 15, 2018 | A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) ... |
| CVE-2018-8414 | HIGH | 8.8 | 74.0% | Aug 15, 2018 | A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows ... |
| CVE-2018-8406 | HIGH | 7.8 | 3.4% | Aug 15, 2018 | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje... |
| CVE-2018-8405 | HIGH | 7.8 | 3.4% | Aug 15, 2018 | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje... |
| CVE-2018-8375 | HIGH | 7.8 | 16.2% | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-8373 | HIGH | 7.5 | 61.9% | Aug 15, 2018 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2018-3615 | HIGH | 7.3 | 6.3% | Aug 14, 2018 | Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow u... |
| CVE-2018-2446 | HIGH | 7.5 | 1.7% | Aug 14, 2018 | Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensi... |
| CVE-2018-10636 | HIGH | 8.8 | 9.5% | Aug 13, 2018 | CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabili... |
| CVE-2018-15139 | HIGH | 8.8 | 19.3% | Aug 13, 2018 | Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote ... |
| CVE-2018-3775 | HIGH | 8.8 | 1.2% | Aug 12, 2018 | Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentia... |
| CVE-2018-11048 | HIGH | 8.1 | 2.1% | Aug 10, 2018 | Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) v... |
| CVE-2018-10925 | HIGH | 8.1 | 2.2% | Aug 9, 2018 | It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check auth... |
| CVE-2018-10915 | HIGH | 8.5 | 5.2% | Aug 9, 2018 | A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its inter... |
| CVE-2018-15133 | HIGH | 8.1 | 76.8% | Aug 9, 2018 | In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri... |
| CVE-2018-11561 | HIGH | 7.5 | 0.9% | Aug 8, 2018 | An integer overflow in the unprotected distributeToken function of a smart contract implementation for EETHER (EETHER), ... |
| CVE-2018-12408 | HIGH | 7.5 | 2.4% | Aug 8, 2018 | The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix Busines... |
| CVE-2018-5390 | HIGH | 7.5 | 73.5% | Aug 6, 2018 | Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queu... |
| CVE-2018-14716 | HIGH | 7.5 | 33.0% | Aug 6, 2018 | A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques... |
| CVE-2018-14576 | HIGH | 7.5 | 1.6% | Aug 3, 2018 | The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow v... |
| CVE-2018-1524 | HIGH | 8.8 | 1.9% | Aug 3, 2018 | IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now