2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3710 | HIGH | 7.8 | 2.9% | Mar 21, 2018 | Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project impor... |
| CVE-2018-8822 | HIGH | 7.8 | 0.5% | Mar 20, 2018 | Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through... |
| CVE-2018-1221 | HIGH | 8.1 | 1.2% | Mar 19, 2018 | In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket reque... |
| CVE-2018-1195 | HIGH | 8.8 | 1.0% | Mar 19, 2018 | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 28... |
| CVE-2018-1171 | HIGH | 7 | 0.4% | Mar 19, 2018 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-2... |
| CVE-2018-5476 | HIGH | 7.8 | 1.7% | Mar 15, 2018 | A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.0... |
| CVE-2018-2402 | HIGH | 7.6 | 1.6% | Mar 14, 2018 | In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more ... |
| CVE-2018-2398 | HIGH | 7.5 | 1.0% | Mar 14, 2018 | Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restr... |
| CVE-2018-1437 | HIGH | 7.8 | 2.3% | Mar 14, 2018 | IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to mul... |
| CVE-2018-1435 | HIGH | 7.8 | 2.6% | Mar 14, 2018 | IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a ma... |
| CVE-2018-1386 | HIGH | 7.8 | 0.3% | Mar 14, 2018 | IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with im... |
| CVE-2018-1057 | HIGH | 8.8 | 10.3% | Mar 13, 2018 | On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modi... |
| CVE-2018-6312 | HIGH | 7.2 | 1.3% | Mar 10, 2018 | A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15... |
| CVE-2018-7236 | HIGH | 8.1 | 1.3% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7235 | HIGH | 7.5 | 1.6% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7234 | HIGH | 7.5 | 1.0% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7230 | HIGH | 8.8 | 1.6% | Mar 9, 2018 | A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Elect... |
| CVE-2018-0209 | HIGH | 7.7 | 1.6% | Mar 8, 2018 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X ... |
| CVE-2018-5452 | HIGH | 7.5 | 2.1% | Mar 7, 2018 | A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Co... |
| CVE-2018-7746 | HIGH | 8.8 | 3.3% | Mar 7, 2018 | An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/chann... |
| CVE-2018-7745 | HIGH | 7.5 | 12.5% | Mar 7, 2018 | An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst... |
| CVE-2018-7720 | HIGH | 8.8 | 1.2% | Mar 7, 2018 | A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/create... |
| CVE-2018-7185 | HIGH | 7.5 | 9.2% | Mar 6, 2018 | The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by ... |
| CVE-2018-7712 | HIGH | 7.5 | 2.3% | Mar 5, 2018 | The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cau... |
| CVE-2018-7560 | HIGH | 7.5 | 1.4% | Mar 4, 2018 | index.js in the Anton Myshenin aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of S... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now