2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1084 | HIGH | 7.5 | 3.2% | Apr 12, 2018 | corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. |
| CVE-2018-1079 | HIGH | 8.7 | 1.1% | Apr 12, 2018 | pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The... |
| CVE-2018-1029 | HIGH | 7.8 | 20.3% | Apr 12, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-1027 | HIGH | 7.8 | 19.5% | Apr 12, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje... |
| CVE-2018-3888 | HIGH | 7.8 | 1.5% | Apr 11, 2018 | A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ... |
| CVE-2018-3887 | HIGH | 7.8 | 1.5% | Apr 11, 2018 | A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ... |
| CVE-2018-3886 | HIGH | 7.8 | 1.5% | Apr 11, 2018 | A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ... |
| CVE-2018-10054 | HIGH | 8.8 | 35.0% | Apr 11, 2018 | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can... |
| CVE-2018-1100 | HIGH | 7.8 | 0.5% | Apr 11, 2018 | zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local ... |
| CVE-2018-0022 | HIGH | 7.5 | 2.3% | Apr 11, 2018 | A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when ... |
| CVE-2018-0021 | HIGH | 8.8 | 0.6% | Apr 11, 2018 | If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CA... |
| CVE-2018-0020 | HIGH | 7.5 | 1.4% | Apr 11, 2018 | Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash... |
| CVE-2018-0018 | HIGH | 7.5 | 1.5% | Apr 11, 2018 | On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to b... |
| CVE-2018-0017 | HIGH | 7.5 | 1.9% | Apr 11, 2018 | A vulnerability in the Network Address Translation - Protocol Translation (NAT-PT) feature of Junos OS on SRX series dev... |
| CVE-2018-3839 | HIGH | 8.8 | 2.6% | Apr 10, 2018 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer ... |
| CVE-2018-9989 | HIGH | 7.5 | 2.1% | Apr 10, 2018 | ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that co... |
| CVE-2018-9988 | HIGH | 7.5 | 2.1% | Apr 10, 2018 | ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() tha... |
| CVE-2018-2408 | HIGH | 7.3 | 1.6% | Apr 10, 2018 | Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Laun... |
| CVE-2018-9331 | HIGH | 7.5 | 2.6% | Apr 7, 2018 | An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory trave... |
| CVE-2018-1272 | HIGH | 7.5 | 2.8% | Apr 6, 2018 | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide c... |
| CVE-2018-1421 | HIGH | 7.1 | 1.4% | Apr 4, 2018 | IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection... |
| CVE-2018-0986 | HIGH | 8.8 | 61.5% | Apr 4, 2018 | A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci... |
| CVE-2018-9240 | HIGH | 7.5 | 1.9% | Apr 3, 2018 | ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends ... |
| CVE-2018-6661 | HIGH | 7.8 | 0.8% | Apr 2, 2018 | DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain... |
| CVE-2018-0177 | HIGH | 7.5 | 3.9% | Mar 28, 2018 | A vulnerability in the IP Version 4 (IPv4) processing code of Cisco IOS XE Software running on Cisco Catalyst 3850 and C... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now