2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-2582 | MEDIUM | 6.5 | 4.8% | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions t... |
| CVE-2018-2581 | MEDIUM | 4.7 | 2.6% | Jan 18, 2018 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected ar... |
| CVE-2018-5747 | MEDIUM | 5.5 | 1.3% | Jan 17, 2018 | In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers ... |
| CVE-2018-5686 | MEDIUM | 5.5 | 1.5% | Jan 14, 2018 | In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-p... |
| CVE-2018-5376 | MEDIUM | 6.1 | 0.8% | Jan 12, 2018 | Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter. |
| CVE-2018-0014 | MEDIUM | 4.3 | 0.6% | Jan 10, 2018 | Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of... |
| CVE-2018-0013 | MEDIUM | 6.5 | 1.2% | Jan 10, 2018 | A local file inclusion vulnerability in Juniper Networks Junos Space Network Management Platform may allow an authentica... |
| CVE-2018-0011 | MEDIUM | 5.4 | 0.8% | Jan 10, 2018 | A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to... |
| CVE-2018-0009 | MEDIUM | 5.4 | 1.3% | Jan 10, 2018 | On Juniper Networks SRX series devices, firewall rules configured to match custom application UUIDs starting with zeros ... |
| CVE-2018-0008 | MEDIUM | 6.2 | 0.5% | Jan 10, 2018 | An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device admini... |
| CVE-2018-0006 | MEDIUM | 6.5 | 0.7% | Jan 10, 2018 | A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high me... |
| CVE-2018-0004 | MEDIUM | 6.5 | 1.2% | Jan 10, 2018 | A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service c... |
| CVE-2018-0003 | MEDIUM | 6.5 | 0.9% | Jan 10, 2018 | A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store in... |
| CVE-2018-5281 | MEDIUM | 5.4 | 2.5% | Jan 8, 2018 | SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV D... |
| CVE-2018-5280 | MEDIUM | 5.4 | 2.5% | Jan 8, 2018 | SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens. |
| CVE-2018-5269 | MEDIUM | 5.5 | 1.4% | Jan 8, 2018 | In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of... |
| CVE-2018-5268 | MEDIUM | 5.5 | 1.5% | Jan 8, 2018 | In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grf... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now