2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-16890HIGH7.5libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling i...
CVE-2018-18333HIGH7.8A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow a...
CVE-2018-20250HIGH7.8In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o...
CVE-2018-11803HIGH7.5Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an unin...
CVE-2018-15778HIGH8.8Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-li...
CVE-2018-1970HIGH7.1IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML da...
CVE-2018-16482HIGH7.5A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to acce...
CVE-2018-3956HIGH7.1An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Softwa...
CVE-2018-16880HIGH7A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under ...
CVE-2018-19015HIGH7.3An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 a...
CVE-2018-19009HIGH7.8Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system conta...
CVE-2018-16881HIGH7.5A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted ...
CVE-2018-19634HIGH7.5CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey informatio...
CVE-2018-15784HIGH7.4Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properl...
CVE-2018-15982HIGH7.8Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful...
CVE-2018-2019HIGH7.1IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when...
CVE-2018-18814HIGH8.8The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketpla...
CVE-2018-18813HIGH8.8The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TI...
CVE-2018-5740HIGH7.5"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS...
CVE-2018-5734HIGH7.5While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcod...
CVE-2018-5733HIGH7.5A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eve...
CVE-2018-15782HIGH7.7The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal...
CVE-2018-16886HIGH8.1etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-b...
CVE-2018-16865HIGH7.8An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover...
CVE-2018-16864HIGH7.8An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now