2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18814HIGH8.8The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketpla...
CVE-2018-18813HIGH8.8The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TI...
CVE-2018-18812MEDIUM6.5The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO...
CVE-2018-5741MEDIUM6.5To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides...
CVE-2018-5740HIGH7.5"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS...
CVE-2018-5739MEDIUM6.5An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certa...
CVE-2018-5738MEDIUM5.3Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, ...
CVE-2018-5737MEDIUM5.9A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb....
CVE-2018-5736An error in zone database reference counting can lead to an assertion failure if a server which is running an affected v...
CVE-2018-5734HIGH7.5While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcod...
CVE-2018-5733HIGH7.5A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eve...
CVE-2018-15782HIGH7.7The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal...
CVE-2018-3311Vulnerability in the Oracle Retail Xstore Payment component of Oracle Retail Applications (subcomponent: Security). The ...
CVE-2018-3309Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version...
CVE-2018-3305Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen...
CVE-2018-3304Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen...
CVE-2018-3303Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponen...
CVE-2018-3125Vulnerability in the Oracle Retail Merchandising System component of Oracle Retail Applications (subcomponent: Security ...
CVE-2018-20726A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escapi...
CVE-2018-20725A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping o...
CVE-2018-20724A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of uninte...
CVE-2018-20723A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping o...
CVE-2018-20721CRITICAL9.8URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomple...
CVE-2018-20720ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause...
CVE-2018-7603In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerabilit...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now