2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-19274HIGH7.2Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Inject...
CVE-2018-15769HIGH7.5RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series)...
CVE-2018-7362HIGH7.5All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which ma...
CVE-2018-19296HIGH8.8PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
CVE-2018-16621HIGH7.2Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
CVE-2018-6065HIGH8.8Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch...
CVE-2018-17463HIGH8.8Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit...
CVE-2018-3635HIGH7.8Insufficient input validation in installer in Intel Rapid Store Technology (RST) before version 16.7 may allow an unpriv...
CVE-2018-19277HIGH8.8securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 enco...
CVE-2018-8589HIGH7.8An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k ...
CVE-2018-8581HIGH7.4An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of...
CVE-2018-6980HIGH7.2VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authori...
CVE-2018-14657HIGH8.1A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force ...
CVE-2018-12416HIGH7.1The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager c...
CVE-2018-1792HIGH8.8IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local...
CVE-2018-15795HIGH8.1Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating s...
CVE-2018-19183HIGH7.5ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.fr...
CVE-2018-15796HIGH8.1Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote ...
CVE-2018-1834HIGH7.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability tha...
CVE-2018-1802HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared librari...
CVE-2018-1781HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ...
CVE-2018-1780HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 inst...
CVE-2018-1774HIGH8.9IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analyt...
CVE-2018-15448HIGH7.5A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, re...
CVE-2018-19093HIGH7.5An issue has been found in libIEC61850 v1.3. It is a SEGV in ControlObjectClient_setCommandTerminationHandler in client/...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now