2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1680MEDIUM5.9IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong password...
CVE-2018-1640HIGH8.8IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute ...
CVE-2018-1626LOW3.1IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful au...
CVE-2018-1625MEDIUM4.3IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive info...
CVE-2018-1623MEDIUM4IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read...
CVE-2018-1622MEDIUM4.3IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could...
CVE-2018-1618HIGH7.7IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories o...
CVE-2018-3979MEDIUM6.5A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display...
CVE-2018-19113The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)...
CVE-2018-17990An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp ...
CVE-2018-17989A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authent...
CVE-2018-17565Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows att...
CVE-2018-17564A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete c...
CVE-2018-17563A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers t...
CVE-2018-4050HIGH7.8An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, vers...
CVE-2018-5757An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functi...
CVE-2018-8913HIGH7.1Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phi...
CVE-2018-13299MEDIUM4.3Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authen...
CVE-2018-13298MEDIUM4.2Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man...
CVE-2018-13297MEDIUM5.3Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attack...
CVE-2018-13296HIGH7.5Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allow...
CVE-2018-13295MEDIUM4.3Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 a...
CVE-2018-13294MEDIUM4.3Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows rem...
CVE-2018-13293MEDIUM5.9Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2....
CVE-2018-13292MEDIUM4.3Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allo...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now