2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-9556CRITICAL9.8In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This c...
CVE-2018-16792CRITICAL9.1SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file ...
CVE-2018-1002105CRITICAL9.8In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg...
CVE-2018-8787CRITICAL9.8FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function g...
CVE-2018-8786CRITICAL9.8FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function...
CVE-2018-8785CRITICAL9.8FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a...
CVE-2018-8784CRITICAL9.8FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that resu...
CVE-2018-17930CRITICAL9.8A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, wh...
CVE-2018-15441CRITICAL9.4A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote at...
CVE-2018-19410CRITICAL9.8PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privile...
CVE-2018-18439CRITICAL9.8DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traf...
CVE-2018-15761CRITICAL9.9Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which...
CVE-2018-15759CRITICAL9.1Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials...
CVE-2018-19355CRITICAL9.8modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows...
CVE-2018-18805CRITICAL9.8Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
CVE-2018-18761CRITICAL9.8SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
CVE-2018-18755CRITICAL9.8K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up...
CVE-2018-7360CRITICAL9.6All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may a...
CVE-2018-7359CRITICAL9All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by heap-based buffer overflow vulnerability, which...
CVE-2018-16850CRITICAL9.8postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ....
CVE-2018-15439CRITICAL9.8A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass ...
CVE-2018-15394CRITICAL9.8A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthentic...
CVE-2018-15381CRITICAL9.8A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to exe...
CVE-2018-18590CRITICAL9.6A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge conta...
CVE-2018-14667CRITICAL9.8The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now