2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18909xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code ...
CVE-2018-18903Vanilla 2.6.x before 2.6.4 allows remote code execution.
CVE-2018-18915There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted inpu...
CVE-2018-16847HIGH7.8An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cm...
CVE-2018-15762CRITICAL9Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2....
CVE-2018-11062Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin...
CVE-2018-16849LOW3.1A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to d...
CVE-2018-7799A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which c...
CVE-2018-7798HIGH8.2A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which...
CVE-2018-3935HIGH7.5An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A s...
CVE-2018-3934CRITICAL9.8An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D....
CVE-2018-3920MEDIUM6.8An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7...
CVE-2018-3899HIGH7.5An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D...
CVE-2018-3898HIGH7.5An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D...
CVE-2018-3892HIGH8.1An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D...
CVE-2018-3891MEDIUM4.6An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7...
CVE-2018-3890MEDIUM6.8An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D....
CVE-2018-1878MEDIUM5.3IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that co...
CVE-2018-1877MEDIUM6.2IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unenc...
CVE-2018-1876MEDIUM6.2IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control ...
CVE-2018-1846HIGH7.1IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Enti...
CVE-2018-1835HIGH7.1IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when ...
CVE-2018-17922Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log f...
CVE-2018-17918Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a...
CVE-2018-1788MEDIUM4.1IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now