2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-16855HIGH7.5An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigge...
CVE-2018-4040HIGH7.8An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, ver...
CVE-2018-4039HIGH7.8An exploitable out-of-bounds write vulnerability exists in the PNG implementation of Atlantis Word Processor, version 3....
CVE-2018-4038HIGH7.8An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, v...
CVE-2018-3951HIGH7.2An exploitable remote code execution vulnerability exists in the HTTP header-parsing function of the TP-Link TL-R600VPN ...
CVE-2018-3950HIGH8.8An exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VP...
CVE-2018-3949HIGH7.5An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A...
CVE-2018-3948HIGH7.5An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP se...
CVE-2018-1897HIGH8.4IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, ...
CVE-2018-19654HIGH7.5An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in userna...
CVE-2018-12122HIGH7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker...
CVE-2018-12121HIGH7.5Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By...
CVE-2018-12120HIGH8.1Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger...
CVE-2018-12116HIGH7.5Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use uns...
CVE-2018-16857HIGH7.4Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict...
CVE-2018-16853HIGH7.5Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain to crash the KDC when Samba is buil...
CVE-2018-0721HIGH7.7Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Syste...
CVE-2018-17953HIGH7.5A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE L...
CVE-2018-18807HIGH7.6The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerab...
CVE-2018-1905HIGH7.1IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack w...
CVE-2018-19518HIGH7.5University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c...
CVE-2018-19423HIGH7.2Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
CVE-2018-19422HIGH7.2/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca...
CVE-2018-1779HIGH7.5IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not ...
CVE-2018-17906HIGH8.8Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now