2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-4182In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions on CUPS.
CVE-2018-4181In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restriction...
CVE-2018-4180In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restriction...
CVE-2018-4179In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed wi...
CVE-2018-4169In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, an out-of...
CVE-2018-4147In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multipl...
CVE-2018-20132Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-15467MEDIUM6.1A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauth...
CVE-2018-15466MEDIUM5.3A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CP...
CVE-2018-15464MEDIUM5.8A vulnerability in Cisco 900 Series Aggregation Services Router (ASR) software could allow an unauthenticated, remote at...
CVE-2018-15461MEDIUM6.1A vulnerability in the MyWebex component of Cisco Webex Business Suite could allow an unauthenticated, remote attacker t...
CVE-2018-5413Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user,...
CVE-2018-5412Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.
CVE-2018-5403Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the atta...
CVE-2018-15460HIGH8.6A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ES...
CVE-2018-20685MEDIUM5.3In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filenam...
CVE-2018-20684In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the s...
CVE-2018-3703Improper directory permissions in the installer for the Intel(R) SSD Data Center Tool for Windows before v3.0.17 may all...
CVE-2018-18098Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may ...
CVE-2018-12177Improper directory permissions in the ZeroConfig service in Intel(R) PROSet/Wireless WiFi Software before version 20.90....
CVE-2018-12167Firmware update routine in bootloader for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a privileg...
CVE-2018-12166Insufficient write protection in firmware for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a priv...
CVE-2018-15458MEDIUM5.3A vulnerability in the Shell Access Filter feature of Cisco Firepower Management Center (FMC), when used in conjunction ...
CVE-2018-15457MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remo...
CVE-2018-16803In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now