2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18227In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/di...
CVE-2018-18226In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/d...
CVE-2018-18225HIGH7.5In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensu...
CVE-2018-1838MEDIUM5.3IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information ...
CVE-2018-1673MEDIUM6.1IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2018-17929HIGH7.8In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerab...
CVE-2018-17927In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities ...
CVE-2018-12441The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unpriv...
CVE-2018-18258An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any...
CVE-2018-18257An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.ph...
CVE-2018-15766On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will ...
CVE-2018-9206CRITICAL9.8Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
CVE-2018-18215In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.
CVE-2018-18242youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=logi...
CVE-2018-12449The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.
CVE-2018-1745HIGH7.5IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to mis...
CVE-2018-1738HIGH7.1IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive informatio...
CVE-2018-1724MEDIUM5.9IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time d...
CVE-2018-1708MEDIUM6.5IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as p...
CVE-2018-1706MEDIUM5.4IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2018-18240Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine co...
CVE-2018-18062An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remo...
CVE-2018-18061An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager int...
CVE-2018-17784MEDIUM6.1Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic...
CVE-2018-17337Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now