2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6540 | — | — | 2.3% | Feb 2, 2018 | In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function o... |
| CVE-2018-6537 | — | — | 4.1% | Feb 2, 2018 | A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attacke... |
| CVE-2018-6536 | — | — | 0.3% | Feb 2, 2018 | An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to... |
| CVE-2018-6526 | — | — | 4.0% | Feb 2, 2018 | view_all_bug_page.php in MantisBT 2.10.0-development before 2018-02-02 allows remote attackers to discover the full path... |
| CVE-2018-6525 | — | — | 0.4% | Feb 2, 2018 | In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD... |
| CVE-2018-6524 | — | — | 0.4% | Feb 2, 2018 | In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD... |
| CVE-2018-6523 | — | — | 0.4% | Feb 2, 2018 | In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD... |
| CVE-2018-6522 | — | — | 0.4% | Feb 2, 2018 | In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKRgFtXp.SYS) allows local users to cause a denial of service (BS... |
| CVE-2018-6521 | — | — | 3.1% | Feb 2, 2018 | The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encount... |
| CVE-2018-6520 | — | — | 0.9% | Feb 2, 2018 | SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authorit... |
| CVE-2018-6519 | — | — | 1.7% | Feb 2, 2018 | The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial... |
| CVE-2018-1192 | — | — | 1.0% | Feb 1, 2018 | In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions ... |
| CVE-2018-6485 | — | — | 4.8% | Feb 1, 2018 | An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or... |
| CVE-2018-6186 | — | — | 3.1% | Feb 1, 2018 | Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attack... |
| CVE-2018-0511 | — | — | 0.9% | Feb 1, 2018 | Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web scr... |
| CVE-2018-0510 | — | — | 2.0% | Feb 1, 2018 | Buffer overflow in epg search result viewer (kkcald) 0.7.19 and earlier allows remote attackers to perform unintended op... |
| CVE-2018-0509 | — | — | 0.7% | Feb 1, 2018 | Cross-site request forgery (CSRF) vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attack... |
| CVE-2018-0508 | — | — | 0.8% | Feb 1, 2018 | Cross-site scripting vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to inject ... |
| CVE-2018-6470 | — | — | 1.1% | Feb 1, 2018 | Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak. |
| CVE-2018-6484 | — | — | 2.3% | Feb 1, 2018 | In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zi... |
| CVE-2018-6374 | — | — | 0.6% | Jan 31, 2018 | The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 ... |
| CVE-2018-6480 | — | — | 1.3% | Jan 31, 2018 | A type confusion issue was discovered in CCN-lite 2, leading to a memory access violation and a failure of the nonce fea... |
| CVE-2018-6476 | — | — | 4.6% | Jan 31, 2018 | In SUPERAntiSpyware Professional Trial 6.0.1254, the SASKUTIL.SYS driver allows privilege escalation to NT AUTHORITY\SYS... |
| CVE-2018-6475 | — | — | 1.0% | Jan 31, 2018 | In SUPERAntiSpyware Professional Trial 6.0.1254, SUPERAntiSpyware.exe allows DLL hijacking, leading to Escalation of Pri... |
| CVE-2018-6474 | — | — | 0.3% | Jan 31, 2018 | In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now