2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16758MEDIUM5.9Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle at...
CVE-2018-16738LOW3.7tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed i...
CVE-2018-16737MEDIUM5.3tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
CVE-2018-13789An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of file...
CVE-2018-12596Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at...
CVE-2018-12456Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attacker...
CVE-2018-12455Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate...
CVE-2018-12544In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking ...
CVE-2018-12542In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that sho...
CVE-2018-12541MEDIUM6.5In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http reques...
CVE-2018-12410CRITICAL9.8The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may...
CVE-2018-12193MEDIUM5.5Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an u...
CVE-2018-12173Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before fi...
CVE-2018-12172Improper password hashing in firmware in Intel Server Board (S7200AP,S7200APR) and Intel Compute Module (HNS7200AP, HNS7...
CVE-2018-12161Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated ...
CVE-2018-12158Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a pri...
CVE-2018-12153Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5...
CVE-2018-12152Pointer corruption in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x....
CVE-2018-0063MEDIUM6.5A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the mana...
CVE-2018-0062MEDIUM5.3A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service wh...
CVE-2018-0061MEDIUM5.3A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high C...
CVE-2018-0060MEDIUM5.3An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an ...
CVE-2018-0059MEDIUM5.4A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authentic...
CVE-2018-0058MEDIUM5.9Receipt of a specially crafted IPv6 exception packet may be able to trigger a kernel crash (vmcore), causing the device ...
CVE-2018-0057MEDIUM6.1On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now