2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3626 | — | — | 0.3% | Mar 20, 2018 | Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible... |
| CVE-2018-5768 | — | — | 3.6% | Mar 20, 2018 | A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted ... |
| CVE-2018-1141 | — | — | 0.2% | Mar 20, 2018 | When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce se... |
| CVE-2018-8822 | HIGH | 7.8 | 0.5% | Mar 20, 2018 | Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through... |
| CVE-2018-5438 | — | — | 0.5% | Mar 20, 2018 | Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker c... |
| CVE-2018-1322 | — | — | 20.5% | Mar 20, 2018 | An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupporte... |
| CVE-2018-1321 | — | — | 18.0% | Mar 20, 2018 | An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and un... |
| CVE-2018-1294 | — | — | 2.9% | Mar 20, 2018 | If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounc... |
| CVE-2018-8088 | CRITICAL | 9.8 | 15.5% | Mar 20, 2018 | org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass int... |
| CVE-2018-7511 | — | — | 2.1% | Mar 20, 2018 | In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer... |
| CVE-2018-5770 | — | — | 2.8% | Mar 20, 2018 | An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, ... |
| CVE-2018-5717 | — | — | 1.2% | Mar 20, 2018 | Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to u... |
| CVE-2018-4844 | MEDIUM | 6.7 | 0.4% | Mar 20, 2018 | A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI fo... |
| CVE-2018-4843 | MEDIUM | 6.5 | 0.5% | Mar 20, 2018 | A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 4... |
| CVE-2018-1000135 | — | — | 2.1% | Mar 20, 2018 | GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver ... |
| CVE-2018-8821 | — | — | 0.7% | Mar 20, 2018 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafte... |
| CVE-2018-8815 | — | — | 1.4% | Mar 20, 2018 | Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in... |
| CVE-2018-8811 | — | — | 2.2% | Mar 20, 2018 | Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow... |
| CVE-2018-8810 | — | — | 1.1% | Mar 20, 2018 | In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote atta... |
| CVE-2018-8809 | — | — | 1.1% | Mar 20, 2018 | In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers co... |
| CVE-2018-8808 | — | — | 1.1% | Mar 20, 2018 | In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers co... |
| CVE-2018-8807 | — | — | 1.7% | Mar 20, 2018 | In libming 0.4.8, these is a use-after-free in the function decompileCALLFUNCTION of decompile.c. Remote attackers could... |
| CVE-2018-8806 | — | — | 1.5% | Mar 20, 2018 | In libming 0.4.8, there is a use-after-free in the decompileArithmeticOp function of decompile.c. Remote attackers could... |
| CVE-2018-8805 | — | — | 0.7% | Mar 20, 2018 | Yxcms building system (compatible cell phone) v1.4.7 has XSS via the content parameter to protected\apps\default\view\de... |
| CVE-2018-8804 | — | — | 3.8% | Mar 20, 2018 | WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCo... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now