2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11231 | — | — | 9.1% | May 23, 2018 | In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential info... |
| CVE-2018-10357 | — | — | 73.9% | May 23, 2018 | A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to exe... |
| CVE-2018-10356 | — | — | 10.5% | May 23, 2018 | A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker ... |
| CVE-2018-10355 | — | — | 0.6% | May 23, 2018 | An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover ... |
| CVE-2018-10354 | — | — | 13.6% | May 23, 2018 | A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a rem... |
| CVE-2018-10353 | — | — | 1.4% | May 23, 2018 | A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote at... |
| CVE-2018-10352 | — | — | 2.2% | May 23, 2018 | A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL state... |
| CVE-2018-10351 | — | — | 3.7% | May 23, 2018 | A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL state... |
| CVE-2018-1193 | — | — | 1.1% | May 23, 2018 | Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers... |
| CVE-2018-1310 | — | — | 3.2% | May 23, 2018 | Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial... |
| CVE-2018-1309 | — | — | 4.5% | May 23, 2018 | Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or... |
| CVE-2018-1125 | HIGH | 7.5 | 2.2% | May 23, 2018 | procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FO... |
| CVE-2018-1123 | LOW | 3.9 | 9.1% | May 23, 2018 | procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection ... |
| CVE-2018-1122 | HIGH | 7.3 | 1.3% | May 23, 2018 | procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset... |
| CVE-2018-8176 | — | — | 22.1% | May 23, 2018 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly valida... |
| CVE-2018-11396 | — | — | 1.5% | May 23, 2018 | ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial ... |
| CVE-2018-1126 | MEDIUM | 4.8 | 2.0% | May 23, 2018 | procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer... |
| CVE-2018-1124 | HIGH | 7.8 | 1.8% | May 23, 2018 | procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec ... |
| CVE-2018-7295 | — | — | 0.4% | May 23, 2018 | ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Messa... |
| CVE-2018-11334 | — | — | 0.3% | May 23, 2018 | Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of... |
| CVE-2018-11362 | — | — | 3.1% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/diss... |
| CVE-2018-11361 | — | — | 2.9% | May 22, 2018 | In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by a... |
| CVE-2018-11360 | — | — | 3.5% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epa... |
| CVE-2018-11359 | — | — | 2.9% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was ad... |
| CVE-2018-11358 | — | — | 2.8% | May 22, 2018 | In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dis... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now