2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-4404HIGH8.8In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve...
CVE-2018-15460HIGH8.6A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ES...
CVE-2018-15453HIGH8.6A vulnerability in the Secure/Multipurpose Internet Mail Extensions (S/MIME) Decryption and Verification or S/MIME Publi...
CVE-2018-0474HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticat...
CVE-2018-0181HIGH7.3A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Ro...
CVE-2018-16202HIGH8.6Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2...
CVE-2018-16177HIGH7.8Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measu...
CVE-2018-1000412HIGH8.8An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows att...
CVE-2018-20679HIGH7.5An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server...
CVE-2018-2484HIGH8.8SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5....
CVE-2018-1320HIGH7.5Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the...
CVE-2018-5410HIGH7.8Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys dri...
CVE-2018-16882HIGH8.8A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1...
CVE-2018-6347HIGH7.5An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affe...
CVE-2018-6346HIGH7.5A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular...
CVE-2018-6344HIGH7.5A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulner...
CVE-2018-6343HIGH7.5Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of serv...
CVE-2018-6340HIGH8.1The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires con...
CVE-2018-6337HIGH7.5folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in m...
CVE-2018-6336HIGH7.8An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks...
CVE-2018-6335HIGH7.5A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to ...
CVE-2018-18601HIGH8.1The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmwa...
CVE-2018-18600HIGH8.1The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parame...
CVE-2018-20618HIGH8.8ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.
CVE-2018-20549HIGH8.8There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now