2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18365 | — | — | 1.3% | Apr 9, 2019 | Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to dis... |
| CVE-2018-7118 | — | — | 0.5% | Apr 9, 2019 | A local access restriction bypass vulnerability was identified in HPE Service Pack for ProLiant (SPP) Bundled Software e... |
| CVE-2018-7117 | — | — | 1.3% | Apr 9, 2019 | A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out ... |
| CVE-2018-18507 | — | — | — | Apr 9, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-20698 | — | — | 0.8% | Apr 9, 2019 | The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page wh... |
| CVE-2018-19586 | — | — | 5.1% | Apr 9, 2019 | Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered du... |
| CVE-2018-14894 | — | — | 1.9% | Apr 9, 2019 | CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file... |
| CVE-2018-19589 | — | — | 0.7% | Apr 9, 2019 | Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM pr... |
| CVE-2018-13366 | — | — | 0.9% | Apr 9, 2019 | An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial num... |
| CVE-2018-20341 | — | — | 0.3% | Apr 8, 2019 | WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an ... |
| CVE-2018-19006 | — | — | 0.7% | Apr 8, 2019 | OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulne... |
| CVE-2018-20816 | — | — | 0.6% | Apr 5, 2019 | An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 ... |
| CVE-2018-19282 | — | — | 5.6% | Apr 4, 2019 | Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by cra... |
| CVE-2018-18068 | — | — | 3.3% | Apr 4, 2019 | The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 co... |
| CVE-2018-20229 | — | — | 1.7% | Apr 4, 2019 | GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory... |
| CVE-2018-20449 | — | — | 0.4% | Apr 4, 2019 | The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain s... |
| CVE-2018-20222 | — | — | 1.7% | Apr 4, 2019 | XXE issue in Airsonic before 10.1.2 during parse. |
| CVE-2018-10244 | — | — | 1.6% | Apr 4, 2019 | Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code... |
| CVE-2018-10243 | — | — | 2.3% | Apr 4, 2019 | htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer ov... |
| CVE-2018-19981 | — | — | 1.8% | Apr 4, 2019 | Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retr... |
| CVE-2018-13918 | — | — | 0.2% | Apr 4, 2019 | kernel could return a received message length higher than expected, which leads to buffer overflow in a subsequent opera... |
| CVE-2018-11971 | — | — | 0.2% | Apr 4, 2019 | Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asse... |
| CVE-2018-11970 | — | — | 0.2% | Apr 4, 2019 | TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Ele... |
| CVE-2018-11966 | — | — | 0.2% | Apr 4, 2019 | Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon ... |
| CVE-2018-11958 | — | — | 0.2% | Apr 4, 2019 | Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon A... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now