2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-4452HIGH7.8A memory consumption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.3, Sec...
CVE-2018-4451HIGH7.8This issue is fixed in macOS Mojave 10.14. A memory corruption issue was addressed with improved input validation.
CVE-2018-4428HIGH7.1A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting opt...
CVE-2018-11764HIGH8.8Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users m...
CVE-2018-20243HIGH7.5The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomratio...
CVE-2018-5354HIGH8.8The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code an...
CVE-2018-11765HIGH7.5In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets with...
CVE-2018-6448HIGH7.5A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a ...
CVE-2018-10585HIGH7.5Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
CVE-2018-10432HIGH7.5Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
CVE-2018-17145HIGH7.5Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of m...
CVE-2018-13903HIGH8.1u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, S...
CVE-2018-1501HIGH7.5IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missi...
CVE-2018-21036HIGH7.5Sails.js before v1.0.0-46 allows attackers to cause a denial of service with a single request because there is no error ...
CVE-2018-12371HIGH8.8An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l...
CVE-2018-21264HIGH8.8An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. It did not enforce the expiration date of a...
CVE-2018-21263HIGH8.8An issue was discovered in Mattermost Server before 4.7.0, 4.6.2, and 4.5.2. An attacker could authenticate to a differe...
CVE-2018-21262HIGH7.5An issue was discovered in Mattermost Server before 4.7.3. It allows attackers to cause a denial of service (application...
CVE-2018-21258HIGH7.5An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite...
CVE-2018-21248HIGH7.5An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication creden...
CVE-2018-21247HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) i...
CVE-2018-21241HIGH7.8An issue was discovered in Foxit PhantomPDF before 8.3.6. It has an untrusted search path that allows a DLL to execute r...
CVE-2018-21240HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfff...
CVE-2018-21238HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows memory consumption via an ArrayBuffer(0xfffffffe) ca...
CVE-2018-21236HIGH7.5An issue was discovered in Foxit Reader before 2.4.4. It has a NULL pointer dereference.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now