2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1373 | HIGH | 7.5 | 3.2% | Mar 2, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a r... |
| CVE-2018-1058 | HIGH | 8.8 | 14.1% | Mar 2, 2018 | A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker wit... |
| CVE-2018-1170 | HIGH | 8.8 | 0.8% | Mar 2, 2018 | This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installa... |
| CVE-2018-7550 | HIGH | 8.8 | 0.6% | Mar 1, 2018 | The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute a... |
| CVE-2018-7480 | HIGH | 7.8 | 0.4% | Feb 25, 2018 | The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial... |
| CVE-2018-7421 | HIGH | 7.5 | 1.7% | Feb 23, 2018 | In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in... |
| CVE-2018-6488 | HIGH | 8.1 | 1.8% | Feb 22, 2018 | Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could... |
| CVE-2018-1417 | HIGH | 8.1 | 2.2% | Feb 22, 2018 | Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code r... |
| CVE-2018-0139 | HIGH | 8.6 | 2.4% | Feb 22, 2018 | A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice... |
| CVE-2018-7311 | HIGH | 8.8 | 2.3% | Feb 21, 2018 | PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability. The software installs a privileged h... |
| CVE-2018-5716 | HIGH | 8.1 | 1.8% | Feb 21, 2018 | An issue was discovered in Reprise License Manager 11.0. This vulnerability is a Path Traversal where the attacker, by c... |
| CVE-2018-1165 | HIGH | 7 | 0.5% | Feb 21, 2018 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-2... |
| CVE-2018-5379 | HIGH | 7.5 | 39.5% | Feb 19, 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE messa... |
| CVE-2018-5378 | HIGH | 7.1 | 74.4% | Feb 19, 2018 | The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer... |
| CVE-2018-7206 | HIGH | 8.8 | 1.8% | Feb 18, 2018 | An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When usi... |
| CVE-2018-6218 | HIGH | 7 | 1.6% | Feb 16, 2018 | A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary c... |
| CVE-2018-7187 | HIGH | 8.8 | 63.2% | Feb 16, 2018 | The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import pa... |
| CVE-2018-0842 | HIGH | 7 | 1.0% | Feb 15, 2018 | Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, ... |
| CVE-2018-6910 | HIGH | 7.5 | 19.0% | Feb 13, 2018 | DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/in... |
| CVE-2018-6954 | HIGH | 7.8 | 0.5% | Feb 13, 2018 | systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local ... |
| CVE-2018-6860 | HIGH | 8.8 | 2.5% | Feb 12, 2018 | Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a pr... |
| CVE-2018-1000052 | HIGH | 7.5 | 1.4% | Feb 9, 2018 | fmtlib version prior to version 4.1.0 (before commit 0555cea5fc0bf890afe0071a558e44625a34ba85) contains a Memory corrupt... |
| CVE-2018-1000026 | HIGH | 7.7 | 3.9% | Feb 9, 2018 | Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerab... |
| CVE-2018-4878 | HIGH | 7.8 | 89.6% | Feb 6, 2018 | A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to ... |
| CVE-2018-6611 | HIGH | 8.8 | 1.3% | Feb 4, 2018 | soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malfor... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now