2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7864 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7863 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7862 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7861 | — | — | — | Mar 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2018-7997 | — | — | 0.6% | Mar 9, 2018 | Eramba e1.0.6.033 has Reflected XSS on the Error page of the CSV file inclusion tab of the /importTool/preview URI, with... |
| CVE-2018-7996 | — | — | 0.7% | Mar 9, 2018 | Eramba e1.0.6.033 has Stored XSS on the tooltip box via the /programScopes description parameter. |
| CVE-2018-0547 | — | — | 1.5% | Mar 9, 2018 | Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to in... |
| CVE-2018-0546 | — | — | 1.5% | Mar 9, 2018 | Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to in... |
| CVE-2018-0544 | — | — | 1.1% | Mar 9, 2018 | Untrusted search path vulnerability in WinShot 1.53a and earlier (Installer) allows an attacker to gain privileges via a... |
| CVE-2018-0543 | — | — | 0.9% | Mar 9, 2018 | Untrusted search path vulnerability in Jtrim 1.53c and earlier (Installer) allows an attacker to gain privileges via a T... |
| CVE-2018-0525 | — | — | 2.5% | Mar 9, 2018 | Directory traversal vulnerability in Jubatus 1.0.2 and earlier allows remote attackers to read arbitrary files via unspe... |
| CVE-2018-0524 | — | — | 2.1% | Mar 9, 2018 | Jubatus 1.0.2 and earlier allows remote code execution via unspecified vectors. |
| CVE-2018-0523 | — | — | 0.7% | Mar 9, 2018 | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified v... |
| CVE-2018-0522 | — | — | 1.4% | Mar 9, 2018 | Buffer overflow in Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary code via a... |
| CVE-2018-0521 | — | — | 0.8% | Mar 9, 2018 | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary com... |
| CVE-2018-7995 | — | — | 0.3% | Mar 9, 2018 | Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through ... |
| CVE-2018-7894 | — | — | 0.7% | Mar 9, 2018 | Eramba e1.0.6.033 has Reflected XSS in reviews/filterIndex/ThirdPartyRiskReview via the advanced_filter parameter (aka t... |
| CVE-2018-6916 | — | — | 2.2% | Mar 9, 2018 | In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p7, 10.4-STABLE, 10.4-RELEASE-p7, and 10.3-RELEASE-p28, the kernel does not ... |
| CVE-2018-1071 | MEDIUM | 5.5 | 0.4% | Mar 9, 2018 | zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attac... |
| CVE-2018-1069 | — | — | 0.6% | Mar 9, 2018 | Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An ... |
| CVE-2018-7890 | — | — | 79.2% | Mar 8, 2018 | A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The pu... |
| CVE-2018-7889 | — | — | 4.7% | Mar 8, 2018 | gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attacke... |
| CVE-2018-7183 | — | — | 10.8% | Mar 8, 2018 | Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arb... |
| CVE-2018-5313 | — | — | 0.6% | Mar 8, 2018 | A vulnerability allows local attackers to escalate privilege on Rapid Scada 5.5.0 because of weak C:\SCADA permissions. ... |
| CVE-2018-7877 | — | — | 1.3% | Mar 8, 2018 | There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for DOUBLE data. A ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now