2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5735 | HIGH | 7.5 | 1.4% | Oct 30, 2019 | The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions... |
| CVE-2018-19151 | HIGH | 7.5 | 1.3% | Oct 29, 2019 | qtum through 0.16 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends in... |
| CVE-2018-18931 | HIGH | 8.8 | 1.6% | Oct 29, 2019 | An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permi... |
| CVE-2018-18930 | HIGH | 8.8 | 2.8% | Oct 29, 2019 | The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Ma... |
| CVE-2018-18929 | HIGH | 8.8 | 1.1% | Oct 29, 2019 | The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator ... |
| CVE-2018-10727 | MEDIUM | 6.1 | 1.0% | Oct 29, 2019 | Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component ... |
| CVE-2018-3630 | — | — | — | Oct 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2018-7368 | — | — | — | Oct 24, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-3418. Reason: This candidate is a reservation du... |
| CVE-2018-7367 | — | — | — | Oct 24, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-3417. Reason: This candidate is a reservation du... |
| CVE-2018-3300 | MEDIUM | 5.4 | 0.8% | Oct 16, 2019 | Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Internal Operations).... |
| CVE-2018-2875 | MEDIUM | 5 | 1.0% | Oct 16, 2019 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, ... |
| CVE-2018-21028 | HIGH | 7.5 | 2.1% | Oct 11, 2019 | Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function. |
| CVE-2018-21027 | CRITICAL | 9.8 | 2.4% | Oct 11, 2019 | Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled... |
| CVE-2018-20582 | HIGH | 8.8 | 0.7% | Oct 11, 2019 | The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery. |
| CVE-2018-5745 | MEDIUM | 4.9 | 2.3% | Oct 9, 2019 | "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which ... |
| CVE-2018-5744 | HIGH | 7.5 | 3.4% | Oct 9, 2019 | A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affe... |
| CVE-2018-5743 | HIGH | 7.5 | 6.4% | Oct 9, 2019 | By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of al... |
| CVE-2018-5732 | HIGH | 7.5 | 5.0% | Oct 9, 2019 | Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masqu... |
| CVE-2018-21024 | CRITICAL | 9.8 | 2.2% | Oct 8, 2019 | licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request. |
| CVE-2018-21025 | CRITICAL | 9.8 | 2.8% | Oct 8, 2019 | In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrec... |
| CVE-2018-21023 | HIGH | 8.8 | 3.0% | Oct 8, 2019 | getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parame... |
| CVE-2018-21022 | HIGH | 8.8 | 1.8% | Oct 8, 2019 | makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parame... |
| CVE-2018-21021 | HIGH | 8.8 | 1.8% | Oct 8, 2019 | img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter. |
| CVE-2018-21020 | HIGH | 7.5 | 2.0% | Oct 8, 2019 | In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows att... |
| CVE-2018-18379 | MEDIUM | 6.1 | 1.3% | Oct 7, 2019 | The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now