2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15840 | — | — | 1.9% | Mar 29, 2019 | TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets... |
| CVE-2018-20378 | — | — | 2.3% | Mar 29, 2019 | The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow r... |
| CVE-2018-6330 | — | — | 1.6% | Mar 28, 2019 | Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters. |
| CVE-2018-20678 | — | — | 1.4% | Mar 28, 2019 | LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenti... |
| CVE-2018-20144 | — | — | 2.2% | Mar 28, 2019 | GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorre... |
| CVE-2018-19648 | — | — | 1.4% | Mar 27, 2019 | An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged u... |
| CVE-2018-3613 | — | — | 0.4% | Mar 27, 2019 | Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially... |
| CVE-2018-15585 | — | — | 1.5% | Mar 27, 2019 | Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject... |
| CVE-2018-14814 | — | — | 1.5% | Mar 27, 2019 | WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation ... |
| CVE-2018-12183 | — | — | 0.5% | Mar 27, 2019 | Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, in... |
| CVE-2018-12182 | — | — | 0.4% | Mar 27, 2019 | Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalati... |
| CVE-2018-12181 | — | — | 0.4% | Mar 27, 2019 | Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevat... |
| CVE-2018-12180 | — | — | 2.3% | Mar 27, 2019 | Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of priv... |
| CVE-2018-12179 | — | — | 0.4% | Mar 27, 2019 | Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of ... |
| CVE-2018-12178 | — | — | 2.3% | Mar 27, 2019 | Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege an... |
| CVE-2018-19016 | — | — | 3.2% | Mar 27, 2019 | Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and Compac... |
| CVE-2018-18994 | — | — | 1.1% | Mar 27, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file... |
| CVE-2018-12551 | — | — | 1.5% | Mar 27, 2019 | When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any mal... |
| CVE-2018-12550 | — | — | 1.4% | Mar 27, 2019 | When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or... |
| CVE-2018-19466 | — | — | 3.7% | Mar 27, 2019 | A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master passw... |
| CVE-2018-5927 | — | — | 0.4% | Mar 27, 2019 | HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code. |
| CVE-2018-5926 | — | — | 1.2% | Mar 27, 2019 | A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process versio... |
| CVE-2018-5923 | — | — | 2.6% | Mar 27, 2019 | In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution a... |
| CVE-2018-16207 | — | — | 1.3% | Mar 27, 2019 | PowerAct Pro Master Agent for Windows Version 5.13 and earlier allows authenticated attackers to bypass access restricti... |
| CVE-2018-15817 | — | — | 0.8% | Mar 26, 2019 | FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 v... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now