2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-19125PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.
CVE-2018-19124PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 on Windows allows remote attackers to write to arbitrary image...
CVE-2018-19122An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in Ethernet_sendPacket in ethernet_bsd.c.
CVE-2018-19121An issue has been found in libIEC61850 v1.3. It is a SEGV in Ethernet_receivePacket in ethernet_bsd.c.
CVE-2018-1857MEDIUM4.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow a user to bypass FGAC control and gai...
CVE-2018-1842LOW3.6IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verificati...
CVE-2018-1834HIGH7.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha...
CVE-2018-1802HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared librari...
CVE-2018-1799MEDIUM6.2IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local unprivil...
CVE-2018-1781HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ...
CVE-2018-1780HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 inst...
CVE-2018-1774HIGH8.9IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analyt...
CVE-2018-1684MEDIUM5.3IBM WebSphere MQ 8.0 through 9.1 is vulnerable to a error with MQTT topic string publishing that can cause a denial of s...
CVE-2018-7718An issue was discovered in Telexy QPath 5.4.462. A low privileged authenticated user supplying a specially crafted seria...
CVE-2018-19115keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly uns...
CVE-2018-19046keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or...
CVE-2018-19045keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially le...
CVE-2018-19044keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData...
CVE-2018-15451MEDIUM5.4A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remot...
CVE-2018-15450MEDIUM6.5A vulnerability in the web-based UI of Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker...
CVE-2018-6438A Vulnerability in the supportsave command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1....
CVE-2018-6437A Vulnerability in the help command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0...
CVE-2018-6436A Vulnerability in the firmwaredownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1,...
CVE-2018-15449MEDIUM4.3A vulnerability in the web-based management interface of Cisco Video Surveillance Media Server could allow an unauthenti...
CVE-2018-15448HIGH7.5A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, re...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now