2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20125HIGH7.5hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive me...
CVE-2018-19005Cscape, Version 9.80.75.3 SP3 and prior. An improper input validation vulnerability has been identified that may be expl...
CVE-2018-18871Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow...
CVE-2018-15723The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP r...
CVE-2018-15722The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A re...
CVE-2018-15721The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMP...
CVE-2018-15720Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users...
CVE-2018-1160CRITICAL9.8Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking...
CVE-2018-1000886nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-ove...
CVE-2018-1000885PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Ele...
CVE-2018-1000884Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CW...
CVE-2018-1000883Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie v...
CVE-2018-8892A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9...
CVE-2018-8891Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier ...
CVE-2018-8888A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.1...
CVE-2018-15331On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions whe...
CVE-2018-15330On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to...
CVE-2018-15329On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administ...
CVE-2018-19234The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute...
CVE-2018-19233COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name...
CVE-2018-1000882WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result i...
CVE-2018-1000881Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injectio...
CVE-2018-1000880MEDIUM6.5libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: I...
CVE-2018-1000879MEDIUM6.5libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: ...
CVE-2018-1000878HIGH8.8libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now