2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11765 | HIGH | 7.5 | 5.2% | Sep 30, 2020 | In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets with... |
| CVE-2018-6449 | MEDIUM | 6.1 | 0.8% | Sep 25, 2020 | Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could a... |
| CVE-2018-6448 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a ... |
| CVE-2018-6447 | MEDIUM | 5.4 | 0.5% | Sep 25, 2020 | A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.... |
| CVE-2018-10585 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | Pexip Infinity before 18 allows remote Denial of Service (XML parsing). |
| CVE-2018-10432 | HIGH | 7.5 | 1.4% | Sep 25, 2020 | Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP). |
| CVE-2018-20432 | CRITICAL | 9.8 | 3.9% | Sep 14, 2020 | D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows u... |
| CVE-2018-19948 | MEDIUM | 6.5 | 0.3% | Sep 11, 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forge... |
| CVE-2018-19947 | MEDIUM | 6.5 | 0.8% | Sep 11, 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vul... |
| CVE-2018-19946 | MEDIUM | 5.9 | 0.3% | Sep 11, 2020 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate val... |
| CVE-2018-17145 | HIGH | 7.5 | 3.4% | Sep 10, 2020 | Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of m... |
| CVE-2018-17774 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have an insecure NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-17773 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have a buffer overflow via SOCKET_TASK in the NTPT3 protocol. This is fixed in Telium 2 ... |
| CVE-2018-17772 | MEDIUM | 6.8 | 0.7% | Sep 9, 2020 | Ingenico Telium 2 POS terminals allow arbitrary code execution via the TRACE protocol. This is fixed in Telium 2 SDK v9.... |
| CVE-2018-17771 | MEDIUM | 6.6 | 0.5% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-17770 | MEDIUM | 6.6 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol. This is fixe... |
| CVE-2018-17769 | MEDIUM | 6.6 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have a buffer overflow via the 0x26 command of the NTPT3 protocol. This is fixed in Teli... |
| CVE-2018-17768 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have an insecure TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-17767 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-17766 | MEDIUM | 4.6 | 0.5% | Sep 9, 2020 | Ingenico Telium 2 POS Telium2 OS allow bypass of file-reading restrictions via the NTPT3 protocol. This is fixed in Teli... |
| CVE-2018-17765 | MEDIUM | 6.8 | 0.6% | Sep 9, 2020 | Ingenico Telium 2 POS terminals have undeclared TRACE protocol commands. This is fixed in Telium 2 SDK v9.32.03 patch N. |
| CVE-2018-13903 | HIGH | 8.1 | 0.6% | Sep 8, 2020 | u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, S... |
| CVE-2018-12475 | MEDIUM | 5.4 | 0.6% | Sep 1, 2020 | A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUS... |
| CVE-2018-1501 | HIGH | 7.5 | 1.1% | Aug 26, 2020 | IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missi... |
| CVE-2018-1985 | MEDIUM | 4.4 | 0.3% | Aug 24, 2020 | IBM Trusteer Rapport/Apex 3.6.1908.22 contains an unused legacy driver which could allow a user with administrator privi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now