2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8795 | CRITICAL | 9.8 | 7.4% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in f... |
| CVE-2018-8794 | CRITICAL | 9.8 | 6.7% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in functio... |
| CVE-2018-8793 | CRITICAL | 9.8 | 7.1% | Feb 5, 2019 | rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that... |
| CVE-2018-4056 | CRITICAL | 9.8 | 3.0% | Feb 5, 2019 | An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.... |
| CVE-2018-20753 | CRITICAL | 9.8 | 29.6% | Feb 5, 2019 | Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers ... |
| CVE-2018-16489 | CRITICAL | 9.8 | 1.8% | Feb 1, 2019 | A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.... |
| CVE-2018-5560 | CRITICAL | 10 | 1.6% | Jan 31, 2019 | A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla ... |
| CVE-2018-20750 | CRITICAL | 9.8 | 3.3% | Jan 30, 2019 | LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-201... |
| CVE-2018-20749 | CRITICAL | 9.8 | 3.2% | Jan 30, 2019 | LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018... |
| CVE-2018-20748 | CRITICAL | 9.8 | 3.2% | Jan 30, 2019 | LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for ... |
| CVE-2018-17431 | CRITICAL | 9.8 | 84.3% | Jan 30, 2019 | Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication... |
| CVE-2018-20721 | CRITICAL | 9.8 | 2.1% | Jan 16, 2019 | URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomple... |
| CVE-2018-6345 | CRITICAL | 9.8 | 1.7% | Jan 15, 2019 | The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively ... |
| CVE-2018-1969 | CRITICAL | 9 | 1.7% | Jan 14, 2019 | IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be autom... |
| CVE-2018-20675 | CRITICAL | 9.8 | 1.8% | Jan 9, 2019 | D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* b... |
| CVE-2018-4012 | CRITICAL | 9 | 2.5% | Jan 3, 2019 | An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. ... |
| CVE-2018-16879 | CRITICAL | 9.8 | 1.1% | Jan 3, 2019 | Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration chann... |
| CVE-2018-20114 | CRITICAL | 9.8 | 6.7% | Jan 2, 2019 | On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can ... |
| CVE-2018-14719 | CRITICAL | 9.8 | 9.7% | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure... |
| CVE-2018-14718 | CRITICAL | 9.8 | 12.7% | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure... |
| CVE-2018-6333 | CRITICAL | 9.8 | 2.3% | Dec 31, 2018 | The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. A... |
| CVE-2018-6331 | CRITICAL | 9.8 | 2.5% | Dec 31, 2018 | Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafte... |
| CVE-2018-6342 | CRITICAL | 9.8 | 2.8% | Dec 31, 2018 | react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a comman... |
| CVE-2018-6334 | CRITICAL | 9.8 | 1.9% | Dec 31, 2018 | Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not ... |
| CVE-2018-18602 | CRITICAL | 9.8 | 1.4% | Dec 31, 2018 | The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now