2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-14653HIGH8.8The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_g...
CVE-2018-1851HIGH7.3IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the s...
CVE-2018-16469HIGH7.5The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Objec...
CVE-2018-4022HIGH7.8A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A sp...
CVE-2018-15688HIGH8.8A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory ...
CVE-2018-15687HIGH7A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary...
CVE-2018-15686HIGH7.8A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution ...
CVE-2018-3971HIGH7.8An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Aler...
CVE-2018-17921HIGH8.8SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair...
CVE-2018-15442HIGH7.8A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, loca...
CVE-2018-11804HIGH7.5Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to sp...
CVE-2018-17935HIGH8.1All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and r...
CVE-2018-16837HIGH7.8Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable sit...
CVE-2018-18559HIGH8.1In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt ...
CVE-2018-1850HIGH8.8IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations wh...
CVE-2018-15756HIGH7.5Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported ver...
CVE-2018-11080HIGH7.3Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The ap...
CVE-2018-0443HIGH7.5A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless ...
CVE-2018-0442HIGH7.5A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless ...
CVE-2018-0441HIGH7.4A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unau...
CVE-2018-0417HIGH7.8A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated,...
CVE-2018-0378HIGH8.6A vulnerability in the Precision Time Protocol (PTP) feature of Cisco Nexus 5500, 5600, and 6000 Series Switches running...
CVE-2018-0456HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could al...
CVE-2018-18445HIGH7.8In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in t...
CVE-2018-0395HIGH8.8A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Softw...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now