2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7523 | — | — | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability. |
| CVE-2018-7521 | — | — | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, use after free vulnerabilities can be exploited when CX Supervisor parse... |
| CVE-2018-7519 | MEDIUM | 5.3 | 0.4% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow. |
| CVE-2018-7517 | — | — | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability... |
| CVE-2018-7515 | MEDIUM | 5.3 | 0.3% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX... |
| CVE-2018-7513 | MEDIUM | 5.3 | 0.4% | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow. |
| CVE-2018-3710 | HIGH | 7.8 | 2.9% | Mar 21, 2018 | Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project impor... |
| CVE-2018-1230 | — | — | 0.7% | Mar 21, 2018 | Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticat... |
| CVE-2018-1229 | — | — | 0.8% | Mar 21, 2018 | Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthentic... |
| CVE-2018-8074 | — | — | 1.5% | Mar 21, 2018 | Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 ... |
| CVE-2018-8073 | — | — | 1.6% | Mar 21, 2018 | Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in... |
| CVE-2018-7269 | — | — | 1.4% | Mar 21, 2018 | The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduc... |
| CVE-2018-1347 | MEDIUM | 5.3 | 0.7% | Mar 21, 2018 | The administrative web interface in NetIQ iManager, versions prior to 3.1, are vulnerable to reflected cross site script... |
| CVE-2018-1346 | LOW | 3.1 | 1.3% | Mar 21, 2018 | Addresses denial of service attack to eDirectory versions prior to 9.1. |
| CVE-2018-1345 | MEDIUM | 5.9 | 0.7% | Mar 21, 2018 | NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack... |
| CVE-2018-1344 | LOW | 3.1 | 0.9% | Mar 21, 2018 | Addresses potential communication downgrade attack in NetIQ iManager versions prior to 3.1 |
| CVE-2018-8883 | — | — | 0.4% | Mar 20, 2018 | Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled a... |
| CVE-2018-8882 | — | — | 0.4% | Mar 20, 2018 | Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a la... |
| CVE-2018-8881 | — | — | 1.1% | Mar 20, 2018 | Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related... |
| CVE-2018-8876 | — | — | 0.4% | Mar 20, 2018 | In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po... |
| CVE-2018-8875 | — | — | 0.4% | Mar 20, 2018 | In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po... |
| CVE-2018-8874 | — | — | 0.4% | Mar 20, 2018 | In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or po... |
| CVE-2018-8873 | — | — | 0.4% | Mar 20, 2018 | In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)... |
| CVE-2018-8832 | — | — | 0.6% | Mar 20, 2018 | enhavo 0.4.0 has XSS via a user-group that contains executable JavaScript code in the user-group name. The XSS attack la... |
| CVE-2018-8828 | — | — | 31.3% | Mar 20, 2018 | A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now