2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3834 | HIGH | 7.4 | 0.5% | Aug 2, 2018 | An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013. The firmwa... |
| CVE-2018-10922 | HIGH | 7.5 | 0.9% | Aug 2, 2018 | An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of se... |
| CVE-2018-1336 | HIGH | 7.5 | 20.6% | Aug 2, 2018 | An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the d... |
| CVE-2018-3939 | HIGH | 8.8 | 2.3% | Aug 1, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.... |
| CVE-2018-3924 | HIGH | 8.8 | 44.1% | Aug 1, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2018-3847 | HIGH | 8.8 | 2.8% | Aug 1, 2018 | Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version... |
| CVE-2018-8034 | HIGH | 7.5 | 21.3% | Aug 1, 2018 | The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions ... |
| CVE-2018-1595 | HIGH | 8.8 | 2.4% | Aug 1, 2018 | IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary com... |
| CVE-2018-10897 | HIGH | 8.1 | 5.7% | Aug 1, 2018 | A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote... |
| CVE-2018-10896 | HIGH | 7.1 | 0.4% | Aug 1, 2018 | The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init'... |
| CVE-2018-3923 | HIGH | 7.8 | 1.5% | Aug 1, 2018 | A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.54. A specially ... |
| CVE-2018-3922 | HIGH | 7.8 | 1.5% | Aug 1, 2018 | A memory corruption vulnerability exists in the ANI-parsing functionality of Computerinsel Photoline 20.54. A specially ... |
| CVE-2018-3921 | HIGH | 7.8 | 1.5% | Aug 1, 2018 | A memory corruption vulnerability exists in the PSD-parsing functionality of Computerinsel Photoline 20.54. A specially ... |
| CVE-2018-10898 | HIGH | 8.8 | 0.9% | Jul 30, 2018 | A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director usin... |
| CVE-2018-10903 | HIGH | 7.5 | 2.6% | Jul 30, 2018 | A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a m... |
| CVE-2018-13280 | HIGH | 7.4 | 0.6% | Jul 30, 2018 | Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) ... |
| CVE-2018-14678 | HIGH | 7.8 | 0.4% | Jul 28, 2018 | An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback en... |
| CVE-2018-1056 | HIGH | 7.8 | 1.4% | Jul 27, 2018 | An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP fil... |
| CVE-2018-10878 | HIGH | 7.8 | 0.8% | Jul 26, 2018 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of se... |
| CVE-2018-10901 | HIGH | 7.8 | 0.5% | Jul 26, 2018 | A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the prev... |
| CVE-2018-10900 | HIGH | 7.8 | 5.1% | Jul 26, 2018 | Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac... |
| CVE-2018-8090 | HIGH | 7.8 | 1.2% | Jul 25, 2018 | Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bi... |
| CVE-2018-11060 | HIGH | 8.8 | 3.0% | Jul 24, 2018 | RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authentic... |
| CVE-2018-11059 | HIGH | 8.2 | 1.4% | Jul 24, 2018 | RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote authenticated malic... |
| CVE-2018-5387 | HIGH | 7.5 | 1.7% | Jul 24, 2018 | Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now