2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8930 | — | — | 1.8% | Mar 22, 2018 | The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Valida... |
| CVE-2018-5225 | — | — | 3.6% | Mar 22, 2018 | In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through ... |
| CVE-2018-0552 | — | — | 1.0% | Mar 22, 2018 | Untrusted search path vulnerability in The installer of PhishWall Client Firefox and Chrome edition for Windows Ver. 5.1... |
| CVE-2018-0542 | — | — | 2.3% | Mar 22, 2018 | Directory traversal vulnerability in WebProxy version 1.7.8 allows an attacker to read arbitrary files via unspecified v... |
| CVE-2018-0541 | — | — | 3.2% | Mar 22, 2018 | Buffer overflow in Tiny FTP Daemon Ver0.52d allows an attacker to cause a denial-of-service (DoS) condition or execute a... |
| CVE-2018-0540 | — | — | 1.0% | Mar 22, 2018 | Untrusted search path vulnerability in ViX version 2.21.148.0 allows an attacker to gain privileges via a Trojan horse D... |
| CVE-2018-0539 | — | — | 2.7% | Mar 22, 2018 | QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors. |
| CVE-2018-0538 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via ... |
| CVE-2018-0537 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via ... |
| CVE-2018-0536 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via ... |
| CVE-2018-0535 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in PHP 2chBBS version bbs18c allows an attacker to inject arbitrary web script or HTM... |
| CVE-2018-0534 | — | — | 0.7% | Mar 22, 2018 | Cross-site scripting vulnerability in ArsenoL Version 0.5 allows an attacker to inject arbitrary web script or HTML via ... |
| CVE-2018-1448 | HIGH | 7.7 | 0.4% | Mar 22, 2018 | IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability tha... |
| CVE-2018-1428 | MEDIUM | 6.2 | 0.3% | Mar 22, 2018 | IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algori... |
| CVE-2018-1427 | MEDIUM | 6.2 | 0.5% | Mar 22, 2018 | IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a ... |
| CVE-2018-1426 | HIGH | 7.4 | 2.5% | Mar 22, 2018 | IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system... |
| CVE-2018-8909 | — | — | 2.0% | Mar 22, 2018 | The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads direc... |
| CVE-2018-8899 | — | — | 1.3% | Mar 22, 2018 | IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorizati... |
| CVE-2018-8906 | — | — | 0.7% | Mar 22, 2018 | dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishan... |
| CVE-2018-8905 | HIGH | 8.8 | 3.1% | Mar 22, 2018 | In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF fi... |
| CVE-2018-8904 | — | — | 0.4% | Mar 22, 2018 | In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users ... |
| CVE-2018-8896 | — | — | 0.4% | Mar 22, 2018 | In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) o... |
| CVE-2018-8895 | — | — | 0.4% | Mar 22, 2018 | In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) o... |
| CVE-2018-8894 | — | — | 0.4% | Mar 22, 2018 | In 2345 Security Guard 3.6, the driver file (2345BdPcSafe.sys) allows local users to cause a denial of service (BSOD) or... |
| CVE-2018-7525 | — | — | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untru... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now