2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19949 | CRITICAL | 9.8 | 24.4% | Oct 28, 2020 | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has alre... |
| CVE-2018-19943 | MEDIUM | 5.4 | 17.7% | Oct 28, 2020 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has al... |
| CVE-2018-4474 | HIGH | 7.5 | 1.7% | Oct 27, 2020 | A memory consumption issue was addressed with improved memory handling. This issue is fixed in iCloud for Windows 7.7, w... |
| CVE-2018-4468 | MEDIUM | 5.5 | 0.7% | Oct 27, 2020 | This issue was addressed by removing additional entitlements. This issue is fixed in macOS Mojave 10.14.1, Security Upda... |
| CVE-2018-4467 | HIGH | 7.8 | 0.8% | Oct 27, 2020 | A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.3, Sec... |
| CVE-2018-4452 | HIGH | 7.8 | 1.2% | Oct 27, 2020 | A memory consumption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.3, Sec... |
| CVE-2018-4451 | HIGH | 7.8 | 0.9% | Oct 27, 2020 | This issue is fixed in macOS Mojave 10.14. A memory corruption issue was addressed with improved input validation. |
| CVE-2018-4448 | MEDIUM | 5.5 | 0.3% | Oct 27, 2020 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.4, ... |
| CVE-2018-4444 | MEDIUM | 6.5 | 1.1% | Oct 27, 2020 | A logic issue was addressed with improved state management. This issue is fixed in Safari 12.0.2, iOS 12.1.1, tvOS 12.1.... |
| CVE-2018-4433 | MEDIUM | 5.5 | 0.7% | Oct 27, 2020 | A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Mojave 10.14.4, Security ... |
| CVE-2018-4428 | HIGH | 7.1 | 0.3% | Oct 27, 2020 | A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting opt... |
| CVE-2018-4391 | MEDIUM | 5.5 | 0.9% | Oct 27, 2020 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sie... |
| CVE-2018-4390 | MEDIUM | 5.5 | 0.9% | Oct 27, 2020 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS High Sie... |
| CVE-2018-4381 | MEDIUM | 5.5 | 0.6% | Oct 27, 2020 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in tvOS 12.1, iOS 12.1. Pr... |
| CVE-2018-4339 | MEDIUM | 5.5 | 0.3% | Oct 27, 2020 | This issue was addressed with a new entitlement. This issue is fixed in iOS 12.1. A local user may be able to read a per... |
| CVE-2018-4296 | CRITICAL | 9.8 | 1.0% | Oct 27, 2020 | This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was addressed with addit... |
| CVE-2018-21269 | MEDIUM | 5.5 | 0.4% | Oct 27, 2020 | checkpath in OpenRC through 0.42.1 might allow local users to take ownership of arbitrary files because a non-terminal p... |
| CVE-2018-8062 | MEDIUM | 5.4 | 1.0% | Oct 23, 2020 | A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware... |
| CVE-2018-21267 | — | — | — | Oct 22, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-21266 | — | — | — | Oct 22, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-18508 | MEDIUM | 6.5 | 2.0% | Oct 22, 2020 | In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a nul... |
| CVE-2018-11764 | HIGH | 8.8 | 2.4% | Oct 21, 2020 | Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users m... |
| CVE-2018-20243 | HIGH | 7.5 | 2.6% | Oct 13, 2020 | The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomratio... |
| CVE-2018-5354 | HIGH | 8.8 | 2.7% | Sep 30, 2020 | The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code an... |
| CVE-2018-5353 | CRITICAL | 9.8 | 8.1% | Sep 30, 2020 | The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execu... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now