2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8756 | — | — | 3.4% | Mar 18, 2018 | Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary cod... |
| CVE-2018-8754 | MEDIUM | 5.5 | 0.3% | Mar 18, 2018 | The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly c... |
| CVE-2018-8741 | — | — | 4.5% | Mar 17, 2018 | A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete)... |
| CVE-2018-8737 | — | — | 0.5% | Mar 17, 2018 | Bookme Control Panel 2.0 Application is vulnerable to stored XSS within the Customers "Book Me" function. Within the Nam... |
| CVE-2018-8740 | — | — | 8.2% | Mar 17, 2018 | In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL point... |
| CVE-2018-3561 | — | — | 0.1% | Mar 16, 2018 | In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race c... |
| CVE-2018-3560 | — | — | 0.1% | Mar 16, 2018 | In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Double... |
| CVE-2018-1200 | — | — | 1.4% | Mar 16, 2018 | Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) ... |
| CVE-2018-1199 | MEDIUM | 5.3 | 2.9% | Mar 16, 2018 | Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.... |
| CVE-2018-1078 | — | — | 1.3% | Mar 16, 2018 | OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffi... |
| CVE-2018-8739 | — | — | 1.6% | Mar 16, 2018 | VPN Unlimited 4.2.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. The ... |
| CVE-2018-1068 | MEDIUM | 6.7 | 0.5% | Mar 16, 2018 | A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privi... |
| CVE-2018-7544 | — | — | 1.9% | Mar 16, 2018 | A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interfac... |
| CVE-2018-1000134 | — | — | 4.9% | Mar 16, 2018 | UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d2136789... |
| CVE-2018-1000133 | — | — | 1.4% | Mar 16, 2018 | Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that... |
| CVE-2018-1324 | MEDIUM | 5.5 | 3.7% | Mar 16, 2018 | A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field par... |
| CVE-2018-5476 | HIGH | 7.8 | 1.7% | Mar 15, 2018 | A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.0... |
| CVE-2018-7033 | — | — | 2.1% | Mar 15, 2018 | SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD. |
| CVE-2018-1319 | — | — | 2.3% | Mar 15, 2018 | In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a mali... |
| CVE-2018-6957 | — | — | 1.7% | Mar 15, 2018 | VMware Workstation (14.x before 14.1.1, 12.x) and Fusion (10.x before 10.1.1 and 8.x) contain a denial-of-service vulner... |
| CVE-2018-6231 | — | — | 7.2% | Mar 15, 2018 | A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) ... |
| CVE-2018-6230 | — | — | 3.5% | Mar 15, 2018 | A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an ... |
| CVE-2018-6229 | — | — | 10.8% | Mar 15, 2018 | A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker ... |
| CVE-2018-6228 | — | — | 10.8% | Mar 15, 2018 | A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to exe... |
| CVE-2018-6227 | — | — | 1.7% | Mar 15, 2018 | A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now