2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16496 | MEDIUM | 5.3 | 0.7% | May 26, 2021 | In Versa Director, the un-authentication request found. |
| CVE-2018-16495 | HIGH | 8.8 | 0.9% | May 26, 2021 | In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not change... |
| CVE-2018-16494 | HIGH | 8.8 | 1.9% | May 26, 2021 | In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through in... |
| CVE-2018-10868 | HIGH | 7.5 | 1.1% | May 26, 2021 | redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allo... |
| CVE-2018-10867 | CRITICAL | 9.1 | 1.1% | May 26, 2021 | Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an a... |
| CVE-2018-10866 | CRITICAL | 9.1 | 1.0% | May 26, 2021 | It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it ... |
| CVE-2018-10865 | HIGH | 7.5 | 1.0% | May 26, 2021 | It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it ... |
| CVE-2018-10863 | HIGH | 7.5 | 1.1% | May 26, 2021 | It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /... |
| CVE-2018-25014 | CRITICAL | 9.8 | 2.2% | May 21, 2021 | A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol(). |
| CVE-2018-25013 | CRITICAL | 9.1 | 2.1% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes(). |
| CVE-2018-25012 | CRITICAL | 9.1 | 2.1% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). |
| CVE-2018-25011 | CRITICAL | 9.8 | 2.5% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16(). |
| CVE-2018-25010 | CRITICAL | 9.1 | 2.2% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter(). |
| CVE-2018-25009 | CRITICAL | 9.1 | 2.1% | May 21, 2021 | A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). |
| CVE-2018-25007 | MEDIUM | 4.3 | 0.6% | Apr 23, 2021 | Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0... |
| CVE-2018-19942 | MEDIUM | 6.1 | 0.7% | Apr 16, 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, t... |
| CVE-2018-25008 | MEDIUM | 5.9 | 1.1% | Apr 14, 2021 | In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchroniz... |
| CVE-2018-1110 | HIGH | 7.5 | 1.1% | Mar 30, 2021 | A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service. |
| CVE-2018-1109 | MEDIUM | 5.3 | 1.4% | Mar 30, 2021 | A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vuln... |
| CVE-2018-1107 | MEDIUM | 5.3 | 1.2% | Mar 30, 2021 | It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON f... |
| CVE-2018-25004 | MEDIUM | 4.9 | 1.0% | Mar 1, 2021 | A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain co... |
| CVE-2018-3633 | — | — | — | Feb 25, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-10349 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-10348 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-10347 | — | — | — | Jan 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now