2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6311 | MEDIUM | 6.8 | 0.3% | Mar 10, 2018 | One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UAR... |
| CVE-2018-7239 | — | — | 2.9% | Mar 9, 2018 | A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in a... |
| CVE-2018-7238 | CRITICAL | 9.8 | 2.8% | Mar 9, 2018 | A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmw... |
| CVE-2018-7237 | CRITICAL | 9.1 | 1.7% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7236 | HIGH | 8.1 | 1.3% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7235 | HIGH | 7.5 | 1.6% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7234 | HIGH | 7.5 | 1.0% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7233 | CRITICAL | 9.8 | 2.1% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7232 | CRITICAL | 9.8 | 2.1% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7231 | CRITICAL | 9.8 | 2.1% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7230 | HIGH | 8.8 | 1.6% | Mar 9, 2018 | A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Elect... |
| CVE-2018-7229 | CRITICAL | 9.8 | 2.2% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7228 | CRITICAL | 9.8 | 2.2% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7227 | MEDIUM | 5.3 | 1.2% | Mar 9, 2018 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ... |
| CVE-2018-7582 | — | — | 37.6% | Mar 9, 2018 | WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to ... |
| CVE-2018-7581 | — | — | 1.1% | Mar 9, 2018 | \ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUIL... |
| CVE-2018-7537 | — | — | 4.6% | Mar 9, 2018 | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Tru... |
| CVE-2018-7536 | — | — | 4.8% | Mar 9, 2018 | An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.ur... |
| CVE-2018-7290 | — | — | 0.5% | Mar 9, 2018 | Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1. |
| CVE-2018-8002 | — | — | 8.5% | Mar 9, 2018 | In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.... |
| CVE-2018-8001 | — | — | 1.3% | Mar 9, 2018 | In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attac... |
| CVE-2018-8000 | — | — | 2.9% | Mar 9, 2018 | In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfT... |
| CVE-2018-7999 | — | — | 2.3% | Mar 9, 2018 | In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRend... |
| CVE-2018-7998 | — | — | 1.9% | Mar 9, 2018 | In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate functio... |
| CVE-2018-7865 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now