2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-14667CRITICAL9.8The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou...
CVE-2018-15762CRITICAL9Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2....
CVE-2018-3934CRITICAL9.8An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D....
CVE-2018-17916CRITICAL9.8InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to...
CVE-2018-17914CRITICAL9.8InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to...
CVE-2018-16840CRITICAL9.8A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy ...
CVE-2018-16462CRITICAL10A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shel...
CVE-2018-14558CRITICAL9.8An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware throu...
CVE-2018-17903CRITICAL9.1SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
CVE-2018-14816CRITICAL9.8Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified,...
CVE-2018-4013CRITICAL9.8An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l...
CVE-2018-15758CRITICAL9.6Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0...
CVE-2018-14807CRITICAL9.8A stack-based buffer overflow vulnerability in Opto 22 PAC Control Basic and PAC Control Professional versions R10.0a an...
CVE-2018-1822CRITICAL9.8IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the syste...
CVE-2018-15616CRITICAL9A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perf...
CVE-2018-10824CRITICAL9.8An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2....
CVE-2018-10933CRITICAL9.1A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul...
CVE-2018-3183CRITICAL9Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Scripting). Supported...
CVE-2018-17890CRITICAL9.8NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, w...
CVE-2018-9206CRITICAL9.8Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
CVE-2018-12410CRITICAL9.8The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may...
CVE-2018-0044CRITICAL9.8An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remot...
CVE-2018-17963CRITICAL9.8qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause ...
CVE-2018-18084CRITICAL9.8An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter...
CVE-2018-14649CRITICAL9.8It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug she...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now