2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10675 | HIGH | 7.8 | 0.4% | May 2, 2018 | The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial o... |
| CVE-2018-10665 | — | — | 1.2% | May 2, 2018 | ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files. |
| CVE-2018-10657 | — | — | 1.5% | May 2, 2018 | Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 ... |
| CVE-2018-9302 | — | — | 10.8% | May 2, 2018 | SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r... |
| CVE-2018-5520 | — | — | 1.1% | May 2, 2018 | On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell... |
| CVE-2018-5519 | — | — | 1.1% | May 2, 2018 | On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.3, or 11.2.1-11.6.3.1, administrative users by way of undisclosed methods ca... |
| CVE-2018-5518 | — | — | 0.4% | May 2, 2018 | On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest can cause a disruption... |
| CVE-2018-5517 | — | — | 1.8% | May 2, 2018 | On F5 BIG-IP 13.1.0-13.1.0.5, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an in... |
| CVE-2018-5516 | — | — | 0.3% | May 2, 2018 | On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.2, or 11.2.1-11.6.3.1, Enterprise Manager 3.1.1, BIG-IQ Centralized Management... |
| CVE-2018-5515 | — | — | 3.4% | May 2, 2018 | On F5 BIG-IP 13.0.0-13.1.0.5, using RADIUS authentication responses from a RADIUS server with IPv6 addresses may cause T... |
| CVE-2018-5514 | — | — | 4.0% | May 2, 2018 | On F5 BIG-IP 13.1.0-13.1.0.5, maliciously crafted HTTP/2 request frames can lead to denial of service. There is data pla... |
| CVE-2018-5512 | — | — | 3.1% | May 2, 2018 | On F5 BIG-IP 13.1.0-13.1.0.5, when Large Receive Offload (LRO) and SYN cookies are enabled (default settings), undisclos... |
| CVE-2018-1468 | — | — | 1.0% | May 2, 2018 | IBM API Connect 5.0.8.1 and 5.0.8.2 could allow a user to get access to internal environment and sensitive API details t... |
| CVE-2018-6401 | — | — | 1.2% | May 2, 2018 | Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a ... |
| CVE-2018-10647 | — | — | 0.4% | May 2, 2018 | SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. T... |
| CVE-2018-10646 | — | — | 0.4% | May 2, 2018 | CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" serv... |
| CVE-2018-10645 | — | — | 0.4% | May 2, 2018 | Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVP... |
| CVE-2018-10642 | — | — | 7.5% | May 2, 2018 | Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary co... |
| CVE-2018-10544 | — | — | 1.2% | May 2, 2018 | Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface. |
| CVE-2018-6242 | — | — | 2.7% | May 1, 2018 | Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery M... |
| CVE-2018-10260 | — | — | 5.8% | May 1, 2018 | A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. |
| CVE-2018-10259 | — | — | 1.6% | May 1, 2018 | An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u... |
| CVE-2018-10258 | — | — | 7.6% | May 1, 2018 | A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to... |
| CVE-2018-10257 | — | — | 4.4% | May 1, 2018 | A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile... |
| CVE-2018-10256 | — | — | 2.6% | May 1, 2018 | A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now