2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11289Data truncation during higher to lower type conversion which causes less memory allocation than desired can lead to a bu...
CVE-2018-20033CRITICAL9.8A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and e...
CVE-2018-20795tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path p...
CVE-2018-20794tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via pat...
CVE-2018-20793tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[...
CVE-2018-20792tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path pa...
CVE-2018-20791tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mis...
CVE-2018-20790tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0]...
CVE-2018-20789tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a pat...
CVE-2018-20788drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has sev...
CVE-2018-20787The ft5x46 touchscreen driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has a...
CVE-2018-20786libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a ...
CVE-2018-20785Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM...
CVE-2018-18692A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary ...
CVE-2018-20784CRITICAL9.8In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denia...
CVE-2018-20783In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR readin...
CVE-2018-2006MEDIUM4.9IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the ...
CVE-2018-1950MEDIUM4.3IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance generates an error message that ...
CVE-2018-1949MEDIUM4.3IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance discloses sensitive information ...
CVE-2018-1948MEDIUM4.3IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not set the secure attribut...
CVE-2018-1947MEDIUM6.1IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance is vulnerable to cross-site scri...
CVE-2018-1946MEDIUM5.9IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance supports interaction between mul...
CVE-2018-1945MEDIUM6.1IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance could allow a remote attacker to...
CVE-2018-1944MEDIUM5.1IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials,...
CVE-2018-6687MEDIUM5.5Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attacker...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now