2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1114MEDIUM6.5It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized whi...
CVE-2018-10935MEDIUM6.5A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with...
CVE-2018-10893HIGH7.6Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames....
CVE-2018-6976MEDIUM5.3The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vu...
CVE-2018-6975The AirWatch Agent for iOS prior to 5.8.1 contains a data protection vulnerability whereby the files and keychain entrie...
CVE-2018-10853HIGH7A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrst...
CVE-2018-16832CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because...
CVE-2018-16831Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in...
CVE-2018-1571HIGH8.8IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sendi...
CVE-2018-16807In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Ke...
CVE-2018-16806A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and possibly other vehicles, relie...
CVE-2018-16805In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link...
CVE-2018-11775TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vu...
CVE-2018-3875CRITICAL9.9An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-14636MEDIUM5.3Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief windo...
CVE-2018-14635MEDIUM6.5When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an...
CVE-2018-14620MEDIUM4.7The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build ...
CVE-2018-16705FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the syst...
CVE-2018-16591FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service acco...
CVE-2018-12608An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both t...
CVE-2018-16802An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running o...
CVE-2018-3897HIGH8.8An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of S...
CVE-2018-3896HIGH8.8An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of S...
CVE-2018-16797A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary cod...
CVE-2018-16608In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/ind...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now