2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20000Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a loca...
CVE-2018-19991VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler...
CVE-2018-19983An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmis...
CVE-2018-19982An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication a...
CVE-2018-19653HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing sett...
CVE-2018-19980Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying A...
CVE-2018-19967An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of servic...
CVE-2018-19966An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash...
CVE-2018-19965An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS cr...
CVE-2018-19964An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because th...
CVE-2018-19963An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly...
CVE-2018-19962An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS pri...
CVE-2018-19961An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS pri...
CVE-2018-9578CRITICAL9.8In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bo...
CVE-2018-9577HIGH7.8In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to...
CVE-2018-9576HIGH7.8In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to mi...
CVE-2018-9575HIGH7.8In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bo...
CVE-2018-9574HIGH7.8In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missi...
CVE-2018-9573HIGH7.8In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds che...
CVE-2018-9572HIGH8.8In impd_drc_parse_coeff of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check...
CVE-2018-9571HIGH8.8In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing b...
CVE-2018-9570HIGH7.8In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds chec...
CVE-2018-9569HIGH8.8In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect b...
CVE-2018-9519In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to l...
CVE-2018-9518In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. T...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now