2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-14847CRITICAL9.1MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated ...
CVE-2018-3881CRITICAL9.4An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticate...
CVE-2018-12468CRITICAL9.1A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attack...
CVE-2018-8859CRITICAL9.8Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i....
CVE-2018-8855CRITICAL9.8Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i....
CVE-2018-8851CRITICAL9.8Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i....
CVE-2018-10627CRITICAL9.8Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i....
CVE-2018-1999019CRITICAL9.8Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint loca...
CVE-2018-6678CRITICAL9.1Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web Gateway (MWG) MWG 7.8...
CVE-2018-6677CRITICAL9.1Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows au...
CVE-2018-10870CRITICAL9.8redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use t...
CVE-2018-10620CRITICAL9.8AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could ...
CVE-2018-7602CRITICAL9.8A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows a...
CVE-2018-0349CRITICAL9.8A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files ...
CVE-2018-2938CRITICAL9Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected a...
CVE-2018-14362CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may h...
CVE-2018-14361CRITICAL9.8An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
CVE-2018-14360CRITICAL9.8An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow becau...
CVE-2018-14359CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data...
CVE-2018-14358CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer ove...
CVE-2018-14357CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute a...
CVE-2018-14356CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
CVE-2018-14354CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute a...
CVE-2018-14353CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an int...
CVE-2018-14352CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not l...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now