2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1000155 | — | — | 1.2% | May 24, 2018 | OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake... |
| CVE-2018-1000040 | — | — | 1.5% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker ... |
| CVE-2018-1000039 | MEDIUM | 6.3 | 1.8% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to exec... |
| CVE-2018-1000038 | — | — | 2.0% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could al... |
| CVE-2018-1000037 | MEDIUM | 5.5 | 1.6% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial... |
| CVE-2018-1000036 | MEDIUM | 5.5 | 1.0% | May 24, 2018 | In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of serv... |
| CVE-2018-11411 | — | — | 1.0% | May 24, 2018 | The transferFrom function of a smart contract implementation for DimonCoin (FUD), an Ethereum ERC20 token, allows attack... |
| CVE-2018-11410 | — | — | 5.1% | May 24, 2018 | An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allow... |
| CVE-2018-11405 | — | — | 0.6% | May 24, 2018 | Kliqqi 2.0.2 has CSRF in admin/admin_users.php. |
| CVE-2018-11404 | — | — | 2.3% | May 24, 2018 | DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter. |
| CVE-2018-11403 | — | — | 1.8% | May 24, 2018 | DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter. |
| CVE-2018-11402 | — | — | 0.2% | May 24, 2018 | SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PI... |
| CVE-2018-11401 | — | — | 0.3% | May 24, 2018 | In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker... |
| CVE-2018-11400 | — | — | 0.3% | May 24, 2018 | In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physicall... |
| CVE-2018-11399 | — | — | 0.2% | May 24, 2018 | SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentia... |
| CVE-2018-10428 | — | — | 2.0% | May 23, 2018 | ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulne... |
| CVE-2018-6495 | MEDIUM | 5.4 | 0.7% | May 23, 2018 | Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0,... |
| CVE-2018-10654 | — | — | 1.2% | May 23, 2018 | There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befo... |
| CVE-2018-10653 | — | — | 6.8% | May 23, 2018 | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befor... |
| CVE-2018-10652 | — | — | 1.2% | May 23, 2018 | There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3. |
| CVE-2018-10651 | — | — | 0.7% | May 23, 2018 | There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-10650 | — | — | 0.8% | May 23, 2018 | There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-10649 | — | — | 0.7% | May 23, 2018 | There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. |
| CVE-2018-10648 | — | — | 1.2% | May 23, 2018 | There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-8898 | — | — | 13.3% | May 23, 2018 | A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B0... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now