2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16880HIGH7A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under ...
CVE-2018-1668MEDIUM5.3IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through ...
CVE-2018-10612In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and co...
CVE-2018-19723Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier...
CVE-2018-19721Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier...
CVE-2018-19014Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C...
CVE-2018-19010Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C...
CVE-2018-19012Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C...
CVE-2018-19015HIGH7.3An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 a...
CVE-2018-19728Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 20...
CVE-2018-19727Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Succe...
CVE-2018-19726Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successf...
CVE-2018-19724Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful ex...
CVE-2018-10910MEDIUM4.5A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with...
CVE-2018-16889MEDIUM5.5Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption ...
CVE-2018-20745Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, whic...
CVE-2018-20744The Olivier Poitrey Go CORS handler through 1.3.0 actively converts a wildcard CORS policy into reflecting an arbitrary ...
CVE-2018-19023Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can le...
CVE-2018-19021MEDIUM6.5A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, ...
CVE-2018-19009HIGH7.8Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system conta...
CVE-2018-16881HIGH7.5A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted ...
CVE-2018-20743murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the data...
CVE-2018-16098In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing ...
CVE-2018-18981In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send nume...
CVE-2018-12237The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vu...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now