2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1720MEDIUM5.9IBM Sterling B2B Integrator Standard Edition 5.2.0.1, 5.2.6.3_6, 6.0.0.0, and 6.0.0.1 uses weaker than expected cryptogr...
CVE-2018-20823The gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20....
CVE-2018-7575Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-...
CVE-2018-7574Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7576, CVE-2018-21233. Reason: this candidate was...
CVE-2018-20434LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm...
CVE-2018-18251Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP...
CVE-2018-7577Memcpy parameter overlap in Google Snappy library 1.1.4, as used in Google TensorFlow before 1.7.1, could result in a cr...
CVE-2018-10055Invalid memory access and/or a heap buffer overflow in the TensorFlow XLA compiler in Google TensorFlow before 1.7.1 cou...
CVE-2018-13443EOS.IO jit-wasm 4.1 has a heap-based buffer overflow via a crafted wast file.
CVE-2018-8825Google TensorFlow 1.7 and below is affected by: Buffer Overflow. The impact is: execute arbitrary code (local).
CVE-2018-7576Google TensorFlow 1.6.x and earlier is affected by: Null Pointer Dereference. The type of exploitation is: context-depen...
CVE-2018-3314Vulnerability in the MICROS Relate CRM Software component of Oracle Retail Applications (subcomponent: Customer). The su...
CVE-2018-3312Vulnerability in the Oracle Retail Customer Engagement component of Oracle Retail Applications (subcomponent: Segment). ...
CVE-2018-3123Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: libmysqld). Supported versions that a...
CVE-2018-3120Vulnerability in the MICROS Lucas component of Oracle Retail Applications (subcomponent: Security). Supported versions t...
CVE-2018-2880Vulnerability in the MICROS Retail-J component of Oracle Retail Applications (subcomponent: Back Office). The supported ...
CVE-2018-1328Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".
CVE-2018-1317In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as o...
CVE-2018-20822MEDIUM6.5LibSass 3.5.4 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Complex_Selector::perform i...
CVE-2018-20821MEDIUM6.5The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in ...
CVE-2018-20820read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime cras...
CVE-2018-20819io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of servi...
CVE-2018-17169An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to rea...
CVE-2018-20818A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It ...
CVE-2018-20817SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now