2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-4935 | HIGH | 8.8 | 26.5% | May 19, 2018 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp... |
| CVE-2018-4932 | HIGH | 8.8 | 5.2% | May 19, 2018 | Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploita... |
| CVE-2018-4920 | HIGH | 8.8 | 7.9% | May 19, 2018 | Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploita... |
| CVE-2018-4919 | HIGH | 8.8 | 7.7% | May 19, 2018 | Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable use after free vulnerability. Successful exploita... |
| CVE-2018-11237 | HIGH | 7.8 | 0.9% | May 18, 2018 | An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier m... |
| CVE-2018-5256 | HIGH | 7.5 | 1.7% | May 18, 2018 | CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes ... |
| CVE-2018-1462 | HIGH | 7.6 | 1.2% | May 17, 2018 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,... |
| CVE-2018-1438 | HIGH | 7.5 | 2.3% | May 17, 2018 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,... |
| CVE-2018-1434 | HIGH | 8.8 | 0.9% | May 17, 2018 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,... |
| CVE-2018-1433 | HIGH | 7.5 | 2.7% | May 17, 2018 | IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,... |
| CVE-2018-1111 | HIGH | 7.5 | 94.5% | May 17, 2018 | DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in ... |
| CVE-2018-7160 | HIGH | 8.8 | 9.9% | May 17, 2018 | The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remo... |
| CVE-2018-7158 | HIGH | 7.5 | 3.4% | May 17, 2018 | The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) ve... |
| CVE-2018-0279 | HIGH | 8.8 | 4.6% | May 17, 2018 | A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could a... |
| CVE-2018-1087 | HIGH | 8 | 0.8% | May 15, 2018 | kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnera... |
| CVE-2018-10990 | HIGH | 8 | 1.1% | May 14, 2018 | On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state ... |
| CVE-2018-1259 | HIGH | 7.5 | 5.3% | May 11, 2018 | Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or e... |
| CVE-2018-1258 | HIGH | 8.8 | 2.4% | May 11, 2018 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization b... |
| CVE-2018-8914 | HIGH | 7.3 | 1.3% | May 10, 2018 | SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote att... |
| CVE-2018-8174 | HIGH | 7.5 | 87.6% | May 9, 2018 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows... |
| CVE-2018-8120 | HIGH | 7 | 73.7% | May 9, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2018-0824 | HIGH | 8.8 | 73.5% | May 9, 2018 | A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized ... |
| CVE-2018-1089 | HIGH | 7.5 | 4.3% | May 9, 2018 | 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needi... |
| CVE-2018-1000168 | HIGH | 7.5 | 10.8% | May 8, 2018 | nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC fr... |
| CVE-2018-1256 | HIGH | 8.1 | 1.6% | May 7, 2018 | Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers th... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now