2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-1334In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different l...
CVE-2018-13999Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administ...
CVE-2018-13998ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
CVE-2018-13997Genann through 2018-07-08 has a SEGV in genann_run in genann.c.
CVE-2018-13996Genann through 2018-07-08 has a stack-based buffer over-read in genann_train in genann.c.
CVE-2018-11049RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled searc...
CVE-2018-11045Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a st...
CVE-2018-0042Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnera...
CVE-2018-0038Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with h...
CVE-2018-10635In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbi...
CVE-2018-10633Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow a...
CVE-2018-10231Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote...
CVE-2018-13989Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable...
CVE-2018-11529VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arb...
CVE-2018-10197There is a time-based blind SQL injection vulnerability in the Access Manager component before 9.18.040 and 10.x before ...
CVE-2018-8007Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of adm...
CVE-2018-0500Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that mig...
CVE-2018-13879A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, t...
CVE-2018-13878An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a u...
CVE-2018-8356A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certif...
CVE-2018-8326A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Feder...
CVE-2018-8325An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ...
CVE-2018-8324An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ...
CVE-2018-8323An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2018-8319A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithm...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now