2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1788MEDIUM4.1IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged...
CVE-2018-1552MEDIUM5.5IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code...
CVE-2018-18897MEDIUM6.5An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as...
CVE-2018-14660MEDIUM6.5A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY x...
CVE-2018-7356MEDIUM5.6All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vul...
CVE-2018-14661MEDIUM6.5It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red ...
CVE-2018-16842MEDIUM4.4Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function ...
CVE-2018-14659MEDIUM6.5The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_...
CVE-2018-14654MEDIUM6.5The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attack...
CVE-2018-14652MEDIUM6.5The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' trans...
CVE-2018-16839MEDIUM4.3Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to ...
CVE-2018-18873MEDIUM5.5An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_...
CVE-2018-13282MEDIUM5.6Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attac...
CVE-2018-13281MEDIUM4.3Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remo...
CVE-2018-0734MEDIUM5.9The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could u...
CVE-2018-17622MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader...
CVE-2018-1767MEDIUM6.1IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnera...
CVE-2018-1766MEDIUM5.4IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerabilit...
CVE-2018-0735MEDIUM5.9The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could...
CVE-2018-18749MEDIUM5.5data-tools through 2017-07-26 has an Integer Overflow leading to an incorrect end value for the write_wchars function.
CVE-2018-18660MEDIUM6.1An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Refle...
CVE-2018-3970MEDIUM5.5An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Al...
CVE-2018-18568MEDIUM5.9Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credentia...
CVE-2018-18566MEDIUM5.3The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive ph...
CVE-2018-18014MEDIUM4.8* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now