2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12896 | — | — | 0.6% | Jul 2, 2018 | An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POS... |
| CVE-2018-12893 | — | — | 0.4% | Jul 2, 2018 | An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen ... |
| CVE-2018-12892 | — | — | 2.6% | Jul 2, 2018 | An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI ... |
| CVE-2018-12891 | — | — | 0.4% | Jul 2, 2018 | An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reaso... |
| CVE-2018-1249 | MEDIUM | 6.5 | 0.9% | Jul 2, 2018 | Dell EMC iDRAC9 versions prior to 3.21.21.21 did not enforce the use of TLS/SSL for a connection to iDRAC web server for... |
| CVE-2018-1244 | HIGH | 8.8 | 3.5% | Jul 2, 2018 | Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injectio... |
| CVE-2018-1243 | HIGH | 7.5 | 1.8% | Jul 2, 2018 | Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.... |
| CVE-2018-12426 | — | — | 5.1% | Jul 2, 2018 | The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution d... |
| CVE-2018-1212 | HIGH | 8.8 | 4.3% | Jul 2, 2018 | The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contai... |
| CVE-2018-10843 | HIGH | 8.5 | 1.4% | Jul 2, 2018 | source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.... |
| CVE-2018-9276 | HIGH | 7.2 | 87.2% | Jul 2, 2018 | An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra... |
| CVE-2018-12577 | — | — | 2.7% | Jul 2, 2018 | The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices al... |
| CVE-2018-12576 | — | — | 0.7% | Jul 2, 2018 | TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking. |
| CVE-2018-12575 | — | — | 2.9% | Jul 2, 2018 | On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface a... |
| CVE-2018-12574 | — | — | 0.5% | Jul 2, 2018 | CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.6... |
| CVE-2018-12529 | — | — | 0.9% | Jul 2, 2018 | An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabil... |
| CVE-2018-12528 | — | — | 1.5% | Jul 2, 2018 | An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for ... |
| CVE-2018-12499 | — | — | 0.5% | Jul 2, 2018 | The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM)... |
| CVE-2018-10076 | — | — | 1.3% | Jul 2, 2018 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remo... |
| CVE-2018-10075 | — | — | 1.3% | Jul 2, 2018 | Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject ... |
| CVE-2018-13056 | — | — | 1.3% | Jul 2, 2018 | An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its ... |
| CVE-2018-13054 | — | — | 2.2% | Jul 2, 2018 | An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows conf... |
| CVE-2018-8039 | — | — | 10.4% | Jul 2, 2018 | It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.... |
| CVE-2018-10874 | HIGH | 7.8 | 0.5% | Jul 2, 2018 | In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command w... |
| CVE-2018-13053 | — | — | 0.5% | Jul 2, 2018 | The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow v... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now