2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1441 | MEDIUM | 6.1 | 0.9% | Mar 14, 2018 | IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.3 and 8.1.4) is vulnerable t... |
| CVE-2018-1050 | MEDIUM | 4.3 | 6.7% | Mar 13, 2018 | All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is co... |
| CVE-2018-7858 | MEDIUM | 5.5 | 0.6% | Mar 12, 2018 | Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged u... |
| CVE-2018-6311 | MEDIUM | 6.8 | 0.3% | Mar 10, 2018 | One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UAR... |
| CVE-2018-7227 | MEDIUM | 5.3 | 1.2% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-1071 | MEDIUM | 5.5 | 0.4% | Mar 9, 2018 | zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attac... |
| CVE-2018-1443 | MEDIUM | 5.9 | 0.4% | Mar 8, 2018 | An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.... |
| CVE-2018-1442 | MEDIUM | 4.3 | 0.8% | Mar 8, 2018 | IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.4) is vulnerable to cross-si... |
| CVE-2018-1387 | MEDIUM | 5.3 | 1.7% | Mar 8, 2018 | IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensiti... |
| CVE-2018-0224 | MEDIUM | 6.7 | 0.5% | Mar 8, 2018 | A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c... |
| CVE-2018-0217 | MEDIUM | 6.7 | 0.9% | Mar 8, 2018 | A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c... |
| CVE-2018-0214 | MEDIUM | 5.3 | 1.0% | Mar 8, 2018 | A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local atta... |
| CVE-2018-7473 | MEDIUM | 6.1 | 0.9% | Mar 7, 2018 | Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attacke... |
| CVE-2018-1000117 | MEDIUM | 6.7 | 1.1% | Mar 7, 2018 | Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in o... |
| CVE-2018-7170 | MEDIUM | 5.3 | 2.8% | Mar 6, 2018 | ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key ... |
| CVE-2018-6529 | MEDIUM | 6.1 | 1.7% | Mar 6, 2018 | XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR... |
| CVE-2018-6528 | MEDIUM | 6.1 | 1.7% | Mar 6, 2018 | XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DI... |
| CVE-2018-6527 | MEDIUM | 6.1 | 1.7% | Mar 6, 2018 | XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous version... |
| CVE-2018-5729 | MEDIUM | 4.7 | 2.6% | Mar 6, 2018 | MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to c... |
| CVE-2018-1062 | MEDIUM | 5.3 | 1.4% | Mar 6, 2018 | A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delet... |
| CVE-2018-7652 | MEDIUM | 6.1 | 1.2% | Mar 4, 2018 | lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS. |
| CVE-2018-6490 | MEDIUM | 5.9 | 2.6% | Mar 2, 2018 | Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could... |
| CVE-2018-2380 | MEDIUM | 6.6 | 29.2% | Mar 1, 2018 | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr... |
| CVE-2018-7557 | MEDIUM | 6.5 | 1.9% | Feb 28, 2018 | The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denia... |
| CVE-2018-7547 | MEDIUM | 4.8 | 0.5% | Feb 27, 2018 | lyadmin 1.x has XSS via the config[WEB_SITE_TITLE] parameter to the /admin.php?s=/admin/config/groupsave.html URI. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now