2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6486 | HIGH | 7.3 | 1.2% | Feb 2, 2018 | XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Se... |
| CVE-2018-6479 | HIGH | 7.5 | 4.6% | Jan 31, 2018 | An issue was discovered on Netwave IP Camera devices. An unauthenticated attacker can crash a device by sending a POST r... |
| CVE-2018-0136 | HIGH | 8.6 | 2.7% | Jan 31, 2018 | A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (... |
| CVE-2018-6195 | HIGH | 7.2 | 3.7% | Jan 30, 2018 | admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPre... |
| CVE-2018-3835 | HIGH | 8.8 | 2.5% | Jan 29, 2018 | An exploitable out of bounds write vulnerability exists in version 2.2 of the Per Face Texture mapping application known... |
| CVE-2018-6383 | HIGH | 8.8 | 13.6% | Jan 29, 2018 | Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but ... |
| CVE-2018-1048 | HIGH | 7.5 | 1.6% | Jan 24, 2018 | It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH ... |
| CVE-2018-6003 | HIGH | 7.5 | 2.8% | Jan 22, 2018 | An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited rec... |
| CVE-2018-5968 | HIGH | 8.1 | 7.0% | Jan 22, 2018 | FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o... |
| CVE-2018-5960 | HIGH | 8.8 | 0.9% | Jan 22, 2018 | Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Catego... |
| CVE-2018-2725 | HIGH | 8.1 | 1.9% | Jan 18, 2018 | Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Servic... |
| CVE-2018-2639 | HIGH | 8.3 | 3.0% | Jan 18, 2018 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte... |
| CVE-2018-2638 | HIGH | 8.3 | 3.4% | Jan 18, 2018 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte... |
| CVE-2018-2637 | HIGH | 7.4 | 4.6% | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versi... |
| CVE-2018-2633 | HIGH | 8.3 | 5.7% | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported vers... |
| CVE-2018-2627 | HIGH | 7.5 | 0.5% | Jan 18, 2018 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected... |
| CVE-2018-2562 | HIGH | 7.1 | 3.4% | Jan 18, 2018 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supported versions that ... |
| CVE-2018-5764 | HIGH | 7.5 | 6.4% | Jan 17, 2018 | The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses,... |
| CVE-2018-5721 | HIGH | 8.8 | 2.0% | Jan 17, 2018 | Stack-based buffer overflow in the ej_update_variables function in router/httpd/web.c on ASUS routers (when using softwa... |
| CVE-2018-5332 | HIGH | 7.8 | 0.4% | Jan 11, 2018 | In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA ... |
| CVE-2018-0012 | HIGH | 7.8 | 0.3% | Jan 10, 2018 | Junos Space is affected by a privilege escalation vulnerability that may allow a local authenticated attacker to gain ro... |
| CVE-2018-0005 | HIGH | 7.4 | 0.7% | Jan 10, 2018 | QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forward traffic instead o... |
| CVE-2018-0002 | HIGH | 8.2 | 1.5% | Jan 10, 2018 | On SRX Series and MX Series devices with a Service PIC with any ALG enabled, a crafted TCP/IP response packet processed ... |
| CVE-2018-0802 | HIGH | 7.8 | 93.3% | Jan 10, 2018 | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow ... |
| CVE-2018-0798 | HIGH | 8.8 | 95.1% | Jan 10, 2018 | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now