2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-14351CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP statu...
CVE-2018-14350CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer ove...
CVE-2018-14349CRITICAL9.8An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response wit...
CVE-2018-12584CRITICAL9.8The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem...
CVE-2018-14087CRITICAL9.8An issue was discovered in a smart contract implementation for EUC (EUC), an Ethereum token. The contract has an integer...
CVE-2018-14086CRITICAL9.8An issue was discovered in a smart contract implementation for SingaporeCoinOrigin (SCO), an Ethereum token. The contrac...
CVE-2018-14084CRITICAL9.8An issue was discovered in a smart contract implementation for MKCB, an Ethereum token. If the owner sets the value of s...
CVE-2018-8847CRITICAL9.8Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote cod...
CVE-2018-1245CRITICAL9RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability wit...
CVE-2018-14009CRITICAL9.8Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
CVE-2018-12463CRITICAL9.8An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows re...
CVE-2018-10895CRITICAL9.3qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute...
CVE-2018-0041CRITICAL9.8Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone ser...
CVE-2018-0040CRITICAL9.8Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys...
CVE-2018-0037CRITICAL9.8Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processi...
CVE-2018-8327CRITICAL9.8A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code ...
CVE-2018-13873CRITICAL9.8An issue was discovered in the HDF HDF5 1.8.20 library. There is a buffer over-read in H5O_chunk_deserialize in H5Ocache...
CVE-2018-5553CRITICAL9.8The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and runn...
CVE-2018-13794CRITICAL9.8A heap-based buffer overflow exists in stbi__bmp_load_cont in stb_image.h in catimg 2.4.0.
CVE-2018-1000620CRITICAL9.8Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() met...
CVE-2018-1000613CRITICAL9.8Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contain...
CVE-2018-11052CRITICAL9.8Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attac...
CVE-2018-12465CRITICAL9.1An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) ...
CVE-2018-12464CRITICAL10A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gatewa...
CVE-2018-1457CRITICAL9.8An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS a...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now