2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19003GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C...
CVE-2018-18984MEDIUM4.6Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI informa...
CVE-2018-18006Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any exte...
CVE-2018-16875MEDIUM5.9The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for eac...
CVE-2018-16874HIGH8.1In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed wi...
CVE-2018-16873HIGH8.1In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed ...
CVE-2018-6707LOW3.7Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5...
CVE-2018-3705Improper directory permissions in the installer for the Intel(R) System Defense Utility (all versions) may allow authent...
CVE-2018-3704Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated u...
CVE-2018-18097Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potent...
CVE-2018-18096Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to pot...
CVE-2018-18093Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged use...
CVE-2018-14623MEDIUM4.3A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to...
CVE-2018-12206Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenti...
CVE-2018-5411Pixar's Tractor software, versions 2.2 and earlier, contain a stored cross-site scripting vulnerability in the field tha...
CVE-2018-15776MEDIUM6.4Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 contain an improper error handling vulnerability. An unauthenticated...
CVE-2018-15774LOW3.8Dell EMC iDRAC7/iDRAC8 versions prior to 2.61.60.60 and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22, and...
CVE-2018-15754MEDIUM4.2Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identi...
CVE-2018-16872MEDIUM5.3A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_par...
CVE-2018-20145Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the def...
CVE-2018-19489MEDIUM4.7v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race conditio...
CVE-2018-19439XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later vers...
CVE-2018-19364MEDIUM5.5hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading ...
CVE-2018-19118Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer...
CVE-2018-19039Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now