2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-21029 | CRITICAL | 9.8 | 3.1% | Oct 30, 2019 | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name ... |
| CVE-2018-21027 | CRITICAL | 9.8 | 2.4% | Oct 11, 2019 | Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled... |
| CVE-2018-21024 | CRITICAL | 9.8 | 2.2% | Oct 8, 2019 | licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request. |
| CVE-2018-21025 | CRITICAL | 9.8 | 2.8% | Oct 8, 2019 | In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrec... |
| CVE-2018-10105 | CRITICAL | 9.8 | 3.9% | Oct 3, 2019 | tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2). |
| CVE-2018-10103 | CRITICAL | 9.8 | 4.1% | Oct 3, 2019 | tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2). |
| CVE-2018-21018 | CRITICAL | 9.8 | 2.6% | Sep 22, 2019 | Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions. |
| CVE-2018-7820 | CRITICAL | 9.8 | 1.0% | Sep 17, 2019 | A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could c... |
| CVE-2018-7081 | CRITICAL | 9.8 | 5.9% | Sep 13, 2019 | A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacke... |
| CVE-2018-17200 | CRITICAL | 9.8 | 5.0% | Sep 11, 2019 | The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via th... |
| CVE-2018-21013 | CRITICAL | 9.8 | 2.0% | Sep 9, 2019 | The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator a... |
| CVE-2018-20961 | CRITICAL | 9.8 | 6.3% | Aug 7, 2019 | In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/func... |
| CVE-2018-11307 | CRITICAL | 9.8 | 5.7% | Jul 9, 2019 | An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a ga... |
| CVE-2018-17842 | CRITICAL | 9.8 | 2.2% | Jun 19, 2019 | SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter. |
| CVE-2018-20469 | CRITICAL | 9.8 | 18.5% | Jun 17, 2019 | An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to... |
| CVE-2018-6349 | CRITICAL | 9.8 | 2.2% | Jun 14, 2019 | When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for ... |
| CVE-2018-20655 | CRITICAL | 9.8 | 2.2% | Jun 14, 2019 | When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a st... |
| CVE-2018-10698 | CRITICAL | 9.8 | 2.3% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This... |
| CVE-2018-18571 | CRITICAL | 9.1 | 2.8% | Jun 5, 2019 | An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 a... |
| CVE-2018-13379 | CRITICAL | 9.8 | 100.0% | Jun 4, 2019 | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.... |
| CVE-2018-7847 | CRITICAL | 9.8 | 3.8% | May 22, 2019 | A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quant... |
| CVE-2018-7846 | CRITICAL | 9.8 | 29.6% | May 22, 2019 | A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon ... |
| CVE-2018-7842 | CRITICAL | 9.8 | 35.0% | May 22, 2019 | A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Mod... |
| CVE-2018-7841 | CRITICAL | 9.8 | 72.5% | May 22, 2019 | A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code... |
| CVE-2018-14839 | CRITICAL | 9.8 | 89.4% | May 14, 2019 | LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attac... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now