2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1259 | HIGH | 7.5 | 5.3% | May 11, 2018 | Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or e... |
| CVE-2018-1258 | HIGH | 8.8 | 2.5% | May 11, 2018 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization b... |
| CVE-2018-1257 | MEDIUM | 6.5 | 3.3% | May 11, 2018 | Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows a... |
| CVE-2018-7248 | MEDIUM | 5.3 | 6.4% | May 11, 2018 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate... |
| CVE-2018-10580 | — | — | 1.6% | May 11, 2018 | The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displ... |
| CVE-2018-10982 | — | — | 0.5% | May 10, 2018 | An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly... |
| CVE-2018-3649 | — | — | 0.6% | May 10, 2018 | DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and... |
| CVE-2018-3617 | — | — | — | May 10, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3691. Reason: This candidate is a reservation ... |
| CVE-2018-3612 | — | — | 0.3% | May 10, 2018 | Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate pri... |
| CVE-2018-1118 | LOW | 2.3 | 0.4% | May 10, 2018 | Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and t... |
| CVE-2018-10981 | — | — | 0.4% | May 10, 2018 | An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infi... |
| CVE-2018-1115 | CRITICAL | 9.1 | 4.0% | May 10, 2018 | postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() func... |
| CVE-2018-10973 | — | — | 0.9% | May 10, 2018 | An integer overflow in the transferMulti function of a smart contract implementation for KoreaShow, an Ethereum ERC20 to... |
| CVE-2018-10706 | — | — | 1.0% | May 10, 2018 | An integer overflow in the transferMulti function of a smart contract implementation for Social Chain (SCA), an Ethereum... |
| CVE-2018-10977 | — | — | 0.4% | May 10, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10976 | — | — | 0.4% | May 10, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10975 | — | — | 0.4% | May 10, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10974 | — | — | 0.4% | May 10, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10972 | — | — | 1.3% | May 10, 2018 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/p... |
| CVE-2018-10971 | — | — | 1.1% | May 10, 2018 | An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote at... |
| CVE-2018-9849 | — | — | 1.0% | May 10, 2018 | Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly proce... |
| CVE-2018-7941 | — | — | 0.8% | May 10, 2018 | Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft spec... |
| CVE-2018-7940 | — | — | 0.3% | May 10, 2018 | Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0... |
| CVE-2018-7933 | — | — | 1.0% | May 10, 2018 | Huawei home gateway products HiRouter-CD20 and WS5200 with the versions before HiRouter-CD20-10 1.9.6 and the versions b... |
| CVE-2018-6254 | — | — | 0.1% | May 10, 2018 | In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improp... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now