2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0854 | — | — | 1.4% | May 9, 2018 | A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device ... |
| CVE-2018-0824 | HIGH | 8.8 | 73.5% | May 9, 2018 | A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized ... |
| CVE-2018-0765 | — | — | 7.7% | May 9, 2018 | A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Co... |
| CVE-2018-10828 | — | — | 1.4% | May 9, 2018 | An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri... |
| CVE-2018-10770 | — | — | 1.6% | May 9, 2018 | download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a logi... |
| CVE-2018-10940 | — | — | 0.5% | May 9, 2018 | The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers... |
| CVE-2018-1089 | HIGH | 7.5 | 4.3% | May 9, 2018 | 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needi... |
| CVE-2018-1228 | — | — | — | May 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-8912 | MEDIUM | 6.5 | 1.0% | May 9, 2018 | Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remo... |
| CVE-2018-8911 | MEDIUM | 6.5 | 1.0% | May 9, 2018 | Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote ... |
| CVE-2018-10683 | CRITICAL | 9.8 | 1.8% | May 9, 2018 | An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm referenc... |
| CVE-2018-10682 | CRITICAL | 9.8 | 8.2% | May 9, 2018 | An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TC... |
| CVE-2018-1119 | — | — | — | May 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10184. Reason: This candidate is a reservation... |
| CVE-2018-10830 | — | — | 1.0% | May 9, 2018 | In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv... |
| CVE-2018-10184 | — | — | 8.4% | May 9, 2018 | An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size set... |
| CVE-2018-10831 | — | — | 0.7% | May 9, 2018 | Z-NOMP before 2018-04-05 has an incorrect Equihash solution verifier that allows attackers to spoof mining shares, as de... |
| CVE-2018-10827 | — | — | 1.8% | May 9, 2018 | LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exi... |
| CVE-2018-10817 | — | — | 0.6% | May 9, 2018 | Severalnines ClusterControl before 1.6.0-4699 allows XSS. |
| CVE-2018-10705 | — | — | 1.1% | May 9, 2018 | The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire cont... |
| CVE-2018-6921 | — | — | 0.3% | May 8, 2018 | In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to user... |
| CVE-2018-6920 | — | — | 0.3% | May 8, 2018 | In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient... |
| CVE-2018-10812 | — | — | 0.2% | May 8, 2018 | The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which... |
| CVE-2018-8897 | — | — | 18.4% | May 8, 2018 | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa... |
| CVE-2018-6511 | MEDIUM | 5.4 | 0.6% | May 8, 2018 | A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i... |
| CVE-2018-6510 | MEDIUM | 5.4 | 0.5% | May 8, 2018 | A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now