2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1262 | — | — | 1.3% | May 15, 2018 | Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation ac... |
| CVE-2018-11094 | — | — | 35.6% | May 15, 2018 | An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/Rebo... |
| CVE-2018-11127 | — | — | 0.5% | May 15, 2018 | e107 2.1.7 has CSRF resulting in arbitrary user deletion. |
| CVE-2018-11126 | — | — | 0.7% | May 15, 2018 | dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account. |
| CVE-2018-11125 | — | — | — | May 15, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-1087 | HIGH | 8 | 0.8% | May 15, 2018 | kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnera... |
| CVE-2018-11105 | — | — | 1.1% | May 15, 2018 | There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka ... |
| CVE-2018-3661 | — | — | 0.3% | May 15, 2018 | Buffer overflow in Intel system Configuration utilities selview.exe and syscfg.exe before version 14 build 11 allows a l... |
| CVE-2018-3634 | MEDIUM | 5.5 | 0.3% | May 15, 2018 | Parameter corruption in NDIS filter driver in Intel Online Connect Access 1.9.22.0 allows an attacker to cause a denial ... |
| CVE-2018-3611 | — | — | 1.6% | May 15, 2018 | Bounds check vulnerability in User Mode Driver in Intel Graphics Driver 15.40.x.4 and 21.20.x.x allows unprivileged user... |
| CVE-2018-1131 | — | — | 1.3% | May 15, 2018 | Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurat... |
| CVE-2018-10825 | — | — | 0.2% | May 15, 2018 | Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turt... |
| CVE-2018-11102 | — | — | 2.6% | May 15, 2018 | An issue was discovered in Libav 12.3. A read access violation in the mov_probe function in libavformat/mov.c allows rem... |
| CVE-2018-11100 | — | — | 1.8% | May 15, 2018 | The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a fi... |
| CVE-2018-11098 | — | — | 1.4% | May 15, 2018 | An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/uplo... |
| CVE-2018-11097 | — | — | 1.1% | May 15, 2018 | An issue was discovered in cloudwu/cstring through 2016-11-09. There is a memory leak vulnerability that could lead to a... |
| CVE-2018-11095 | — | — | 1.8% | May 15, 2018 | The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file si... |
| CVE-2018-11091 | CRITICAL | 9.9 | 3.7% | May 14, 2018 | An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. I... |
| CVE-2018-11090 | — | — | 0.7% | May 14, 2018 | An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker t... |
| CVE-2018-10994 | — | — | 1.4% | May 14, 2018 | js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL. |
| CVE-2018-8843 | — | — | 2.0% | May 14, 2018 | Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing speci... |
| CVE-2018-10991 | — | — | — | May 14, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10990. Reason: This candidate is a reservation... |
| CVE-2018-10990 | HIGH | 8 | 1.1% | May 14, 2018 | On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state ... |
| CVE-2018-10989 | MEDIUM | 6.6 | 1.4% | May 14, 2018 | Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "pa... |
| CVE-2018-10252 | — | — | 0.9% | May 14, 2018 | An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely ge... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now