2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-1784HIGH7.1IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IB...
CVE-2018-1778HIGH7.7IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication i...
CVE-2018-1771HIGH8.4IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in th...
CVE-2018-8653HIGH7.5A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2018-15801HIGH7.4Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation...
CVE-2018-15798HIGH7.6Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unau...
CVE-2018-18999HIGH7.3WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user suppl...
CVE-2018-20227HIGH7.5RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.
CVE-2018-16884HIGH8A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the sa...
CVE-2018-4015HIGH8.1An exploitable vulnerability exists in the HTTP client functionality of the Webroot BrightCloud SDK. The configuration o...
CVE-2018-20196HIGH7.8There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Fr...
CVE-2018-16874HIGH8.1In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed wi...
CVE-2018-16873HIGH8.1In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed ...
CVE-2018-1821HIGH7.1IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a...
CVE-2018-16557HIGH8.2A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (...
CVE-2018-16556HIGH7.5A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (...
CVE-2018-20127HIGH7.5An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary fil...
CVE-2018-6706HIGH7.5Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivi...
CVE-2018-6705HIGH7.8Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local use...
CVE-2018-6704HIGH7.8Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local use...
CVE-2018-16867HIGH7.8A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_da...
CVE-2018-8639HIGH7.8An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2018-8611HIGH7.8An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "...
CVE-2018-2503HIGH7.4By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that shoul...
CVE-2018-2492HIGH7.1SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now