2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19976In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara...
CVE-2018-19975In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in liby...
CVE-2018-19974In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libya...
CVE-2018-19936PrinterOn Enterprise 4.1.4 allows Arbitrary File Deletion.
CVE-2018-19933Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and Ne...
CVE-2018-19828Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
CVE-2018-19036An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could pote...
CVE-2018-18556CRITICAL9.9A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu...
CVE-2018-18555A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to adm...
CVE-2018-16596A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, an...
CVE-2018-14856Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-...
CVE-2018-14855Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-F...
CVE-2018-14854Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-...
CVE-2018-14853A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4...
CVE-2018-14852Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver...
CVE-2018-1891MEDIUM5.4IBM Security Guardium 10 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2018-1889MEDIUM5.4IBM Security Guardium 10.0 and 10.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2018-20172An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbo...
CVE-2018-20171An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php ...
CVE-2018-20027The yaml_parse.load method in Pylearn2 allows code injection.
CVE-2018-19822Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/SharedC...
CVE-2018-19821Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Securit...
CVE-2018-19820Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Roles.j...
CVE-2018-19819Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Rights....
CVE-2018-19818Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Contact...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now