2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20122The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1....
CVE-2018-20146An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could...
CVE-2018-15380HIGH8.8A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent atta...
CVE-2018-5819An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can b...
CVE-2018-5818An error within the "parse_rollei()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be ...
CVE-2018-5817A type confusion error within the "unpacked_load_raw()" function within LibRaw versions prior to 0.19.1 (internal/dcraw_...
CVE-2018-20030An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be explo...
CVE-2018-20241The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to ...
CVE-2018-20240The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers t...
CVE-2018-19106Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959.
CVE-2018-9867MEDIUM5.5In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administra...
CVE-2018-20026HIGH7.5Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
CVE-2018-20025Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
CVE-2018-1996MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security, caused by the impro...
CVE-2018-3700Code injection vulnerability in the installer for Intel(R) USB 3.0 eXtensible Host Controller Driver for Microsoft Windo...
CVE-2018-12159Buffer overflow in the command-line interface for Intel(R) PROSet Wireless v20.50 and before may allow an authenticated ...
CVE-2018-20782The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.
CVE-2018-1895MEDIUM5.4IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2018-1727HIGH7.1IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attac...
CVE-2018-1701HIGH8.5IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands ...
CVE-2018-6271NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software delivers extra data with the buffe...
CVE-2018-6268NVIDIA Tegra library contains a vulnerability in libnvmmlite_video.so, where referencing memory after it has been freed ...
CVE-2018-6267NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly v...
CVE-2018-19008The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser o...
CVE-2018-20238Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now