2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-3873CRITICAL9.9An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-14643CRITICAL9.8An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can u...
CVE-2018-17254CRITICAL9.8The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
CVE-2018-17232CRITICAL9.8SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 ...
CVE-2018-17207CRITICAL9.8An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and...
CVE-2018-1000802CRITICAL9.8Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements u...
CVE-2018-11058CRITICAL9.8RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C...
CVE-2018-17036CRITICAL9.8An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain par...
CVE-2018-16836CRITICAL9.8Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attac...
CVE-2018-3875CRITICAL9.9An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-16763CRITICAL9.8FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca...
CVE-2018-1567CRITICAL9.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code thro...
CVE-2018-16402CRITICAL9.8libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application cra...
CVE-2018-7791CRITICAL9.8A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all ref...
CVE-2018-7790CRITICAL9.8An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all v...
CVE-2018-15873CRITICAL9.8A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.
CVE-2018-15839CRITICAL9.8D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
CVE-2018-3904CRITICAL9.9An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsun...
CVE-2018-11653CRITICAL9.8Information disclosure in Netwave IP camera at //etc/RT2870STA.dat (via HTTP on port 8000) allows an unauthenticated att...
CVE-2018-3786CRITICAL9.8A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously ...
CVE-2018-14599CRITICAL9.8An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-on...
CVE-2018-11061CRITICAL9.1RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to...
CVE-2018-1722CRITICAL10IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control...
CVE-2018-3907CRITICAL10An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET...
CVE-2018-3880CRITICAL9.9An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of vide...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now