2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3723 | — | — | 2.0% | Jun 7, 2018 | defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which... |
| CVE-2018-3722 | — | — | 2.0% | Jun 7, 2018 | merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which al... |
| CVE-2018-3721 | MEDIUM | 6.5 | 2.4% | Jun 7, 2018 | lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaults... |
| CVE-2018-3720 | HIGH | 8.8 | 2.0% | Jun 7, 2018 | assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which a... |
| CVE-2018-3719 | HIGH | 8.8 | 2.1% | Jun 7, 2018 | mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which al... |
| CVE-2018-3718 | MEDIUM | 5.3 | 1.3% | Jun 7, 2018 | serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is ... |
| CVE-2018-3717 | MEDIUM | 5.4 | 1.3% | Jun 7, 2018 | connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of... |
| CVE-2018-3716 | MEDIUM | 5.4 | 0.6% | Jun 7, 2018 | simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. |
| CVE-2018-3715 | MEDIUM | 6.5 | 1.4% | Jun 7, 2018 | glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to ... |
| CVE-2018-3714 | MEDIUM | 6.5 | 8.6% | Jun 7, 2018 | node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici... |
| CVE-2018-3713 | MEDIUM | 6.5 | 1.5% | Jun 7, 2018 | angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilenam... |
| CVE-2018-3712 | — | — | 1.8% | Jun 7, 2018 | serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and a... |
| CVE-2018-3711 | HIGH | 7.5 | 1.8% | Jun 7, 2018 | Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: a... |
| CVE-2018-5850 | — | — | 0.4% | Jun 6, 2018 | In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow... |
| CVE-2018-5846 | — | — | 0.4% | Jun 6, 2018 | A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA... |
| CVE-2018-5845 | — | — | 0.3% | Jun 6, 2018 | A race condition in drm_atomic_nonblocking_commit() in the display driver can potentially lead to a Use After Free scena... |
| CVE-2018-5841 | — | — | 0.4% | Jun 6, 2018 | dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs ... |
| CVE-2018-5840 | — | — | 0.4% | Jun 6, 2018 | Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android re... |
| CVE-2018-3852 | HIGH | 7.5 | 1.9% | Jun 6, 2018 | An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A sp... |
| CVE-2018-3580 | — | — | 0.4% | Jun 6, 2018 | Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in ... |
| CVE-2018-3578 | — | — | 0.5% | Jun 6, 2018 | Type mismatch for ie_len can cause the WLAN driver to allocate less memory on the heap due to implicit casting leading t... |
| CVE-2018-3565 | — | — | 0.4% | Jun 6, 2018 | While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for M... |
| CVE-2018-3562 | — | — | 0.3% | Jun 6, 2018 | Buffer over -read can occur while processing a FILS authentication frame in all Android releases from CAF (Android for M... |
| CVE-2018-7510 | — | — | 1.4% | Jun 6, 2018 | In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 41076000... |
| CVE-2018-1269 | — | — | 1.1% | Jun 6, 2018 | Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now