2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10509 | — | — | 1.1% | Jun 12, 2018 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh att... |
| CVE-2018-10508 | — | — | 1.3% | Jun 12, 2018 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to eleva... |
| CVE-2018-10507 | — | — | 1.4% | Jun 12, 2018 | A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or ... |
| CVE-2018-10470 | MEDIUM | 5.3 | 0.6% | Jun 12, 2018 | Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllAr... |
| CVE-2018-5814 | — | — | 0.4% | Jun 12, 2018 | In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling ... |
| CVE-2018-5803 | — | — | 0.5% | Jun 12, 2018 | In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_ch... |
| CVE-2018-5718 | — | — | 0.3% | Jun 12, 2018 | Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft Sy... |
| CVE-2018-2428 | MEDIUM | 5.3 | 1.8% | Jun 12, 2018 | Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. S... |
| CVE-2018-2425 | HIGH | 8.4 | 0.4% | Jun 12, 2018 | Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access informati... |
| CVE-2018-2424 | CRITICAL | 9.8 | 2.4% | Jun 12, 2018 | SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided Java... |
| CVE-2018-1103 | MEDIUM | 6.1 | 1.3% | Jun 12, 2018 | Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An att... |
| CVE-2018-12249 | HIGH | 7.5 | 2.1% | Jun 12, 2018 | An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject... |
| CVE-2018-12248 | — | — | 1.6% | Jun 12, 2018 | An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/... |
| CVE-2018-12247 | — | — | 1.6% | Jun 12, 2018 | An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class, related to certain .clone usag... |
| CVE-2018-1075 | MEDIUM | 5 | 0.4% | Jun 12, 2018 | ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engi... |
| CVE-2018-1070 | MEDIUM | 6.5 | 0.8% | Jun 12, 2018 | routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which c... |
| CVE-2018-0732 | HIGH | 7.5 | 49.3% | Jun 12, 2018 | During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime v... |
| CVE-2018-12233 | HIGH | 7.8 | 2.3% | Jun 12, 2018 | In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be trigg... |
| CVE-2018-12232 | — | — | 6.6% | Jun 12, 2018 | In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where ... |
| CVE-2018-12229 | — | — | 1.8% | Jun 12, 2018 | Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 al... |
| CVE-2018-12228 | — | — | 6.8% | Jun 12, 2018 | An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the clien... |
| CVE-2018-12227 | — | — | 3.5% | Jun 12, 2018 | An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Cert... |
| CVE-2018-6968 | — | — | 5.1% | Jun 11, 2018 | The VMware AirWatch Agent for Android prior to 8.2 and AirWatch Agent for Windows Mobile prior to 6.5.2 contain a remote... |
| CVE-2018-6961 | HIGH | 8.1 | 86.4% | Jun 11, 2018 | VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U... |
| CVE-2018-5185 | — | — | 1.6% | Jun 11, 2018 | Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now