2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10841 | HIGH | 8.8 | 1.3% | Jun 20, 2018 | glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could u... |
| CVE-2018-12594 | HIGH | 7.5 | 1.4% | Jun 20, 2018 | Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct reques... |
| CVE-2018-1132 | HIGH | 7.5 | 2.9% | Jun 20, 2018 | A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) wi... |
| CVE-2018-12590 | HIGH | 7.2 | 1.7% | Jun 20, 2018 | Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability du... |
| CVE-2018-11116 | HIGH | 8.8 | 2.4% | Jun 19, 2018 | OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authentic... |
| CVE-2018-10811 | HIGH | 7.5 | 7.4% | Jun 19, 2018 | strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. |
| CVE-2018-12565 | HIGH | 8.8 | 2.5% | Jun 19, 2018 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() wh... |
| CVE-2018-1060 | HIGH | 7.5 | 5.1% | Jun 18, 2018 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib... |
| CVE-2018-6497 | HIGH | 8.8 | 0.6% | Jun 16, 2018 | Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20,... |
| CVE-2018-6496 | HIGH | 8.8 | 0.7% | Jun 16, 2018 | Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, ... |
| CVE-2018-1460 | HIGH | 8.4 | 0.6% | Jun 15, 2018 | IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writa... |
| CVE-2018-7167 | HIGH | 7.5 | 7.2% | Jun 13, 2018 | Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Servic... |
| CVE-2018-7164 | HIGH | 7.5 | 6.4% | Jun 13, 2018 | Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases... |
| CVE-2018-7162 | HIGH | 7.5 | 7.0% | Jun 13, 2018 | All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service ... |
| CVE-2018-7161 | HIGH | 7.5 | 7.9% | Jun 13, 2018 | All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of se... |
| CVE-2018-11806 | HIGH | 8.2 | 0.8% | Jun 13, 2018 | m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams. |
| CVE-2018-1431 | HIGH | 7.4 | 0.4% | Jun 13, 2018 | A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attac... |
| CVE-2018-5432 | HIGH | 8 | 0.9% | Jun 13, 2018 | The TIBCO Administrator server component of of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO... |
| CVE-2018-2425 | HIGH | 8.4 | 0.4% | Jun 12, 2018 | Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access informati... |
| CVE-2018-12249 | HIGH | 7.5 | 2.1% | Jun 12, 2018 | An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject... |
| CVE-2018-0732 | HIGH | 7.5 | 49.3% | Jun 12, 2018 | During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime v... |
| CVE-2018-12233 | HIGH | 7.8 | 2.3% | Jun 12, 2018 | In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be trigg... |
| CVE-2018-6961 | HIGH | 8.1 | 86.4% | Jun 11, 2018 | VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U... |
| CVE-2018-12020 | HIGH | 7.5 | 8.7% | Jun 8, 2018 | mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allo... |
| CVE-2018-4233 | HIGH | 8.8 | 53.8% | Jun 8, 2018 | An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now