2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7494 | — | — | 2.9% | May 4, 2018 | WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than th... |
| CVE-2018-5448 | MEDIUM | 4.8 | 0.7% | May 4, 2018 | Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could... |
| CVE-2018-5446 | MEDIUM | 4.9 | 0.4% | May 4, 2018 | Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format. |
| CVE-2018-10750 | — | — | 3.3% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet... |
| CVE-2018-10749 | — | — | 2.7% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' p... |
| CVE-2018-10748 | — | — | 2.7% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' par... |
| CVE-2018-10747 | — | — | 2.7% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' p... |
| CVE-2018-10746 | — | — | 2.7% | May 4, 2018 | An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' para... |
| CVE-2018-10740 | — | — | 2.8% | May 4, 2018 | Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parame... |
| CVE-2018-9063 | — | — | 0.4% | May 4, 2018 | MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contai... |
| CVE-2018-8872 | — | — | 2.3% | May 4, 2018 | In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory ... |
| CVE-2018-8869 | — | — | 2.3% | May 4, 2018 | In Lantech IDS 2102 2.0 and prior, nearly all input fields allow for arbitrary input on the device. A CVSS v3 base score... |
| CVE-2018-8865 | CRITICAL | 9.8 | 5.9% | May 4, 2018 | In Lantech IDS 2102 2.0 and prior, a stack-based buffer overflow vulnerability has been identified which may allow remot... |
| CVE-2018-8861 | — | — | 0.4% | May 4, 2018 | Vulnerabilities within the Philips Brilliance CT kiosk environment (Brilliance 64 version 2.6.2 and prior, Brilliance iC... |
| CVE-2018-8857 | — | — | 0.3% | May 4, 2018 | Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillanc... |
| CVE-2018-8853 | — | — | 0.4% | May 4, 2018 | Philips Brilliance CT devices operate user functions from within a contained kiosk in a Microsoft Windows operating syst... |
| CVE-2018-7522 | — | — | 0.4% | May 4, 2018 | In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers a... |
| CVE-2018-10739 | — | — | 0.4% | May 4, 2018 | An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe allows local users to bypass intended pro... |
| CVE-2018-10733 | — | — | 2.3% | May 4, 2018 | There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A cra... |
| CVE-2018-10726 | MEDIUM | 5.4 | 0.7% | May 4, 2018 | A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the... |
| CVE-2018-10641 | — | — | 1.8% | May 4, 2018 | D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext. |
| CVE-2018-10562 | CRITICAL | 9.8 | 100.0% | May 4, 2018 | An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac... |
| CVE-2018-10561 | CRITICAL | 9.8 | 93.3% | May 4, 2018 | An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images... |
| CVE-2018-10722 | — | — | 0.5% | May 4, 2018 | In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify... |
| CVE-2018-8003 | — | — | 4.5% | May 3, 2018 | Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now