2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-3828Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered ...
CVE-2018-3827HIGH8.1A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) pl...
CVE-2018-3826In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and...
CVE-2018-3825In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of gran...
CVE-2018-3824X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker i...
CVE-2018-3823MEDIUM5.4X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manag...
CVE-2018-17208Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access,...
CVE-2018-17207CRITICAL9.8An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and...
CVE-2018-17206MEDIUM4.9An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c i...
CVE-2018-17205An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c....
CVE-2018-17204MEDIUM4.3An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in li...
CVE-2018-1782MEDIUM6.5IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node ru...
CVE-2018-17183Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers a...
CVE-2018-16785XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create...
CVE-2018-16607Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote atta...
CVE-2018-14792WECON PLC Editor version 1.3.3U may allow an attacker to execute code under the current process when processing project ...
CVE-2018-12243The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which ...
CVE-2018-12242The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is ...
CVE-2018-1150NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over use...
CVE-2018-1149cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP request...
CVE-2018-8017In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
CVE-2018-5905In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a race condi...
CVE-2018-3574In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, userspace ca...
CVE-2018-3573In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while reloca...
CVE-2018-11904In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, asynchronous...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now