2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-3746CRITICAL9.8The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbi...
CVE-2018-11138CRITICAL9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by...
CVE-2018-11544CRITICAL9.8The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are sto...
CVE-2018-3745CRITICAL9.1atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
CVE-2018-3744CRITICAL9.8The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the s...
CVE-2018-8871CRITICAL9.8In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based bu...
CVE-2018-1000301CRITICAL9.1curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of se...
CVE-2018-9019CRITICAL9.8SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands v...
CVE-2018-4939CRITICAL9.8Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deseria...
CVE-2018-4918CRITICAL9.8Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier hav...
CVE-2018-4917CRITICAL9.8Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier hav...
CVE-2018-10759CRITICAL9.8PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attack...
CVE-2018-8845CRITICAL9.8In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio...
CVE-2018-7499CRITICAL9.8In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio...
CVE-2018-11091CRITICAL9.9An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. I...
CVE-2018-1115CRITICAL9.1postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() func...
CVE-2018-10683CRITICAL9.8An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm referenc...
CVE-2018-10682CRITICAL9.8An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TC...
CVE-2018-10771CRITICAL9.8Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cau...
CVE-2018-10753CRITICAL9.8Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers...
CVE-2018-8865CRITICAL9.8In Lantech IDS 2102 2.0 and prior, a stack-based buffer overflow vulnerability has been identified which may allow remot...
CVE-2018-10562CRITICAL9.8An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac...
CVE-2018-10561CRITICAL9.8An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images...
CVE-2018-2628CRITICAL9.8Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S...
CVE-2018-10191CRITICAL9.8In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_G...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now