2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7269 | — | — | 1.4% | Mar 21, 2018 | The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduc... |
| CVE-2018-8883 | — | — | 0.4% | Mar 20, 2018 | Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled a... |
| CVE-2018-8882 | — | — | 0.4% | Mar 20, 2018 | Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a la... |
| CVE-2018-8881 | — | — | 1.1% | Mar 20, 2018 | Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related... |
| CVE-2018-8876 | — | — | 0.4% | Mar 20, 2018 | In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po... |
| CVE-2018-8875 | — | — | 0.4% | Mar 20, 2018 | In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po... |
| CVE-2018-8874 | — | — | 0.4% | Mar 20, 2018 | In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po... |
| CVE-2018-8873 | — | — | 0.4% | Mar 20, 2018 | In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-8832 | — | — | 0.6% | Mar 20, 2018 | enhavo 0.4.0 has XSS via a user-group that contains executable JavaScript code in the user-group name. The XSS attack la... |
| CVE-2018-8828 | — | — | 31.3% | Mar 20, 2018 | A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially... |
| CVE-2018-3626 | — | — | 0.3% | Mar 20, 2018 | Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible... |
| CVE-2018-5768 | — | — | 3.6% | Mar 20, 2018 | A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted ... |
| CVE-2018-1141 | — | — | 0.2% | Mar 20, 2018 | When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce se... |
| CVE-2018-5438 | — | — | 0.5% | Mar 20, 2018 | Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker c... |
| CVE-2018-1322 | — | — | 20.5% | Mar 20, 2018 | An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupporte... |
| CVE-2018-1321 | — | — | 18.0% | Mar 20, 2018 | An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and un... |
| CVE-2018-1294 | — | — | 2.9% | Mar 20, 2018 | If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounc... |
| CVE-2018-7511 | — | — | 2.1% | Mar 20, 2018 | In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer... |
| CVE-2018-5770 | — | — | 2.8% | Mar 20, 2018 | An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, ... |
| CVE-2018-5717 | — | — | 1.2% | Mar 20, 2018 | Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to u... |
| CVE-2018-1000135 | — | — | 2.1% | Mar 20, 2018 | GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver ... |
| CVE-2018-8821 | — | — | 0.7% | Mar 20, 2018 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafte... |
| CVE-2018-8815 | — | — | 1.4% | Mar 20, 2018 | Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in... |
| CVE-2018-8811 | — | — | 2.2% | Mar 20, 2018 | Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow... |
| CVE-2018-8810 | — | — | 1.1% | Mar 20, 2018 | In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote atta... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now