2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18625 | MEDIUM | 6.1 | 1.2% | Jun 2, 2020 | Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an... |
| CVE-2018-18624 | MEDIUM | 6.1 | 1.4% | Jun 2, 2020 | Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an ... |
| CVE-2018-18623 | MEDIUM | 6.1 | 1.8% | Jun 2, 2020 | Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for ... |
| CVE-2018-21234 | CRITICAL | 9.8 | 8.3% | May 21, 2020 | Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. |
| CVE-2018-10756 | HIGH | 7.8 | 2.6% | May 15, 2020 | Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of ser... |
| CVE-2018-1285 | CRITICAL | 9.8 | 49.8% | May 11, 2020 | Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. Thi... |
| CVE-2018-20225 | HIGH | 7.8 | 1.7% | May 8, 2020 | An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if t... |
| CVE-2018-5484 | — | — | — | May 8, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-5491 | — | — | — | May 8, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-5480 | — | — | — | May 8, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-5493 | HIGH | 7.5 | 1.8% | May 7, 2020 | ATTO FibreBridge 7500N firmware versions prior to 2.90 are susceptible to a vulnerability which allows an unauthenticate... |
| CVE-2018-8956 | MEDIUM | 5.3 | 3.1% | May 6, 2020 | ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchron... |
| CVE-2018-21233 | MEDIUM | 6.5 | 0.5% | May 4, 2020 | TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the co... |
| CVE-2018-21232 | MEDIUM | 5.5 | 1.4% | Apr 29, 2020 | re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags. |
| CVE-2018-21226 | HIGH | 8.8 | 0.7% | Apr 28, 2020 | Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before... |
| CVE-2018-21225 | MEDIUM | 6.8 | 0.8% | Apr 28, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000 before 1.0.1.60, ... |
| CVE-2018-21224 | HIGH | 8.8 | 0.7% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
| CVE-2018-21223 | HIGH | 8.8 | 0.6% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
| CVE-2018-21222 | HIGH | 8.8 | 0.6% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
| CVE-2018-21221 | HIGH | 8.8 | 0.7% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
| CVE-2018-21220 | HIGH | 8.8 | 0.6% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
| CVE-2018-21219 | HIGH | 8.8 | 0.6% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
| CVE-2018-21218 | HIGH | 8.8 | 0.7% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
| CVE-2018-21217 | HIGH | 8.8 | 0.7% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
| CVE-2018-21216 | HIGH | 8.8 | 0.7% | Apr 28, 2020 | Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now