2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1307 | — | — | 1.7% | Feb 9, 2018 | In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML docume... |
| CVE-2018-6878 | — | — | 0.6% | Feb 9, 2018 | Cross Site Scripting (XSS) exists in the review section in PHP Scripts Mall Hot Scripts Clone Script Classified 3.1 via ... |
| CVE-2018-6876 | — | — | 2.5% | Feb 9, 2018 | The OLEProperty class in ole/oleprop.cpp in libfpx 1.3.1-10, as used in ImageMagick 7.0.7-22 Q16 and other products, all... |
| CVE-2018-1401 | — | — | 1.1% | Feb 9, 2018 | IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2018-1368 | — | — | 0.3% | Feb 9, 2018 | IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view r... |
| CVE-2018-6827 | — | — | 0.9% | Feb 9, 2018 | VOBOT CLOCK before 0.99.30 devices do not verify X.509 certificates from SSL servers, which allows man-in-the-middle att... |
| CVE-2018-6826 | — | — | 3.1% | Feb 9, 2018 | An issue was discovered on VOBOT CLOCK before 0.99.30 devices. Cleartext HTTP is used to download a breakout program, an... |
| CVE-2018-6825 | — | — | 1.6% | Feb 9, 2018 | An issue was discovered on VOBOT CLOCK before 0.99.30 devices. An SSH server exists with a hardcoded vobot account that ... |
| CVE-2018-1298 | — | — | 2.4% | Feb 9, 2018 | A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connect... |
| CVE-2018-1055 | — | — | — | Feb 9, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-6871. Reason: This candidate is a reservation ... |
| CVE-2018-1053 | — | — | 0.5% | Feb 9, 2018 | In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg... |
| CVE-2018-1052 | — | — | 1.8% | Feb 9, 2018 | Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticate... |
| CVE-2018-6872 | — | — | 2.2% | Feb 9, 2018 | The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bi... |
| CVE-2018-6871 | — | — | 23.2% | Feb 9, 2018 | LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a... |
| CVE-2018-6869 | — | — | 2.9% | Feb 9, 2018 | In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function o... |
| CVE-2018-6789 | CRITICAL | 9.8 | 82.2% | Feb 8, 2018 | An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes... |
| CVE-2018-6644 | — | — | 1.9% | Feb 8, 2018 | SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /... |
| CVE-2018-6180 | CRITICAL | 9.8 | 4.0% | Feb 8, 2018 | A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password fo... |
| CVE-2018-5550 | — | — | 37.5% | Feb 8, 2018 | Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerabil... |
| CVE-2018-1163 | — | — | 16.3% | Feb 8, 2018 | This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup... |
| CVE-2018-1162 | — | — | 5.0% | Feb 8, 2018 | This vulnerability allows remote attackers to create a denial-of-service condition on vulnerable installations of Quest ... |
| CVE-2018-1161 | — | — | 67.2% | Feb 8, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu... |
| CVE-2018-1000030 | LOW | 3.6 | 1.2% | Feb 8, 2018 | Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 ... |
| CVE-2018-6846 | — | — | 1.5% | Feb 8, 2018 | Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.... |
| CVE-2018-0517 | — | — | 0.9% | Feb 8, 2018 | Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now