2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1368 | — | — | 0.3% | Feb 9, 2018 | IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view r... |
| CVE-2018-6827 | — | — | 0.9% | Feb 9, 2018 | VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle att... |
| CVE-2018-6826 | — | — | 3.1% | Feb 9, 2018 | An issue was discovered on VOBOT CLOCK before 0.99.30 devices. Cleartext HTTP is used to download a breakout program, an... |
| CVE-2018-6825 | — | — | 1.6% | Feb 9, 2018 | An issue was discovered on VOBOT CLOCK before 0.99.30 devices. An SSH server exists with a hardcoded vobot account that ... |
| CVE-2018-1298 | — | — | 2.4% | Feb 9, 2018 | A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connect... |
| CVE-2018-1055 | — | — | — | Feb 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-6871. Reason: This candidate is a reservation ... |
| CVE-2018-1053 | — | — | 0.5% | Feb 9, 2018 | In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg... |
| CVE-2018-1052 | — | — | 1.8% | Feb 9, 2018 | Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticate... |
| CVE-2018-6872 | — | — | 2.2% | Feb 9, 2018 | The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bi... |
| CVE-2018-6871 | — | — | 23.2% | Feb 9, 2018 | LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a... |
| CVE-2018-6869 | — | — | 2.9% | Feb 9, 2018 | In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function o... |
| CVE-2018-6644 | — | — | 1.9% | Feb 8, 2018 | SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /... |
| CVE-2018-5550 | — | — | 37.5% | Feb 8, 2018 | Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerabil... |
| CVE-2018-1163 | — | — | 16.3% | Feb 8, 2018 | This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup... |
| CVE-2018-1162 | — | — | 5.0% | Feb 8, 2018 | This vulnerability allows remote attackers to create a denial-of-service condition on vulnerable installations of Quest ... |
| CVE-2018-1161 | — | — | 67.2% | Feb 8, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu... |
| CVE-2018-6846 | — | — | 1.5% | Feb 8, 2018 | Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.... |
| CVE-2018-0517 | — | — | 0.9% | Feb 8, 2018 | Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker ... |
| CVE-2018-0514 | — | — | 2.3% | Feb 8, 2018 | MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via u... |
| CVE-2018-0513 | — | — | 0.8% | Feb 8, 2018 | Cross-site scripting vulnerability in MTS Simple Booking C, MTS Simple Booking Business version 1.28.0 and earlier allow... |
| CVE-2018-0512 | — | — | 0.7% | Feb 8, 2018 | Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to ... |
| CVE-2018-6844 | — | — | 0.6% | Feb 8, 2018 | MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen. |
| CVE-2018-6836 | — | — | 2.8% | Feb 8, 2018 | The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an un... |
| CVE-2018-6835 | — | — | 2.3% | Feb 8, 2018 | node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass ... |
| CVE-2018-6834 | — | — | 0.9% | Feb 8, 2018 | static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now