2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-16877HIGH7.8A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0...
CVE-2018-7340HIGH7.5Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs...
CVE-2018-4007HIGH7.1An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig fun...
CVE-2018-4006HIGH7.8An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig func...
CVE-2018-4005HIGH7.8An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRouting...
CVE-2018-16561HIGH7.5A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly valida...
CVE-2018-4009HIGH7.8An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of c...
CVE-2018-4008HIGH7.8An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the RunVpncScript co...
CVE-2018-19453HIGH8.8Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
CVE-2018-15640HIGH8.8Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers t...
CVE-2018-4344HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, mac...
CVE-2018-1936HIGH8.4IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds...
CVE-2018-4049HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” dir...
CVE-2018-3974HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's install dir...
CVE-2018-1640HIGH8.8IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute ...
CVE-2018-1618HIGH7.7IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories o...
CVE-2018-4050HIGH7.8An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, vers...
CVE-2018-8913HIGH7.1Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phi...
CVE-2018-13296HIGH7.5Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allow...
CVE-2018-13285HIGH7.5Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated...
CVE-2018-13284HIGH7.5Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authentic...
CVE-2018-13283HIGH8.8Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 all...
CVE-2018-19879HIGH7.1An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The ...
CVE-2018-12545HIGH7.5In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client se...
CVE-2018-16858HIGH7.8It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now