2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-9145 | — | — | 1.9% | Mar 30, 2018 | In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer... |
| CVE-2018-9144 | — | — | 1.9% | Mar 30, 2018 | In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial... |
| CVE-2018-9143 | — | — | 2.4% | Mar 30, 2018 | On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code... |
| CVE-2018-9142 | — | — | 0.8% | Mar 30, 2018 | On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area... |
| CVE-2018-9141 | — | — | 2.4% | Mar 30, 2018 | On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary... |
| CVE-2018-9140 | — | — | 0.6% | Mar 30, 2018 | On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary fi... |
| CVE-2018-9139 | — | — | 2.5% | Mar 30, 2018 | On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privi... |
| CVE-2018-9138 | — | — | 1.1% | Mar 30, 2018 | An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion ... |
| CVE-2018-9136 | — | — | 0.8% | Mar 30, 2018 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafte... |
| CVE-2018-9135 | — | — | 2.1% | Mar 30, 2018 | In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c. |
| CVE-2018-9133 | — | — | 3.3% | Mar 30, 2018 | ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), whi... |
| CVE-2018-9132 | — | — | 1.7% | Mar 30, 2018 | libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leve... |
| CVE-2018-9130 | — | — | 0.7% | Mar 30, 2018 | IBOS 4.4.3 has XSS via a company full name. |
| CVE-2018-1191 | — | — | 0.9% | Mar 29, 2018 | Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access ... |
| CVE-2018-9031 | — | — | 1.6% | Mar 29, 2018 | The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd =="... |
| CVE-2018-6588 | MEDIUM | 6.1 | 0.9% | Mar 29, 2018 | CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to th... |
| CVE-2018-6587 | MEDIUM | 6.1 | 0.9% | Mar 29, 2018 | CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to th... |
| CVE-2018-6586 | MEDIUM | 6.1 | 0.9% | Mar 29, 2018 | CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profi... |
| CVE-2018-5224 | — | — | 2.8% | Mar 29, 2018 | Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating syst... |
| CVE-2018-5223 | — | — | 2.2% | Mar 29, 2018 | Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows ... |
| CVE-2018-4841 | CRITICAL | 9.8 | 4.9% | Mar 29, 2018 | A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port... |
| CVE-2018-9117 | — | — | 2.7% | Mar 29, 2018 | WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyo... |
| CVE-2018-9116 | — | — | 2.0% | Mar 29, 2018 | An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and in... |
| CVE-2018-7600 | CRITICAL | 9.8 | 100.0% | Mar 29, 2018 | Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi... |
| CVE-2018-9123 | — | — | 0.5% | Mar 29, 2018 | In Crea8social 2018.2, there is Stored Cross-Site Scripting via a User Profile. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now