2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18561An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h23...
CVE-2018-18440DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem ...
CVE-2018-18439CRITICAL9.8DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traf...
CVE-2018-16224Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to ret...
CVE-2018-16223Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application th...
CVE-2018-16222Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2....
CVE-2018-12038An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key...
CVE-2018-12037An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA...
CVE-2018-17948An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
CVE-2018-1779HIGH7.5IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not ...
CVE-2018-19367Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already crea...
CVE-2018-19335Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b...
CVE-2018-19334Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b...
CVE-2018-10099Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected b...
CVE-2018-17906HIGH8.8Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials ...
CVE-2018-9209Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
CVE-2018-9207Arbitrary file upload in jQuery Upload File <= 4.0.2
CVE-2018-1841MEDIUM6.2IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/mas...
CVE-2018-17190In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then r...
CVE-2018-15761CRITICAL9.9Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which...
CVE-2018-15759CRITICAL9.1Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials...
CVE-2018-18519BestXsoftware Best Free Keylogger before 6.0.0 allows local users to gain privileges via a Trojan horse "%PROGRAMFILES%\...
CVE-2018-19355CRITICAL9.8modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows...
CVE-2018-19358GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bu...
CVE-2018-19353The ansilove_ansi function in loaders/ansi.c in libansilove 1.0.0 allows remote attackers to cause a denial of service (...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now