2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-16232HIGH8.8An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. Th...
CVE-2018-10823HIGH8.8An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02...
CVE-2018-10822HIGH7.5Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L t...
CVE-2018-18436HIGH8.8JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.
CVE-2018-3955HIGH7.2An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware ...
CVE-2018-3954HIGH7.2Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version...
CVE-2018-3953HIGH7.2Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version...
CVE-2018-17911HIGH7.8LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remo...
CVE-2018-3209HIGH8.3Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). The supported version that is affected ...
CVE-2018-3169HIGH8.3Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions t...
CVE-2018-3149HIGH8.3Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported vers...
CVE-2018-6974HIGH8.8VMware ESXi (6.7 before ESXi670-201810101-SG, 6.5 before ESXi650-201808401-BG, and 6.0 before ESXi600-201808401-BG), Wor...
CVE-2018-1747HIGH7.1IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack ...
CVE-2018-1744HIGH7.7IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the s...
CVE-2018-8890HIGH7.5An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an att...
CVE-2018-1844HIGH7.1IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processin...
CVE-2018-18225HIGH7.5In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensu...
CVE-2018-17929HIGH7.8In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerab...
CVE-2018-1745HIGH7.5IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to mis...
CVE-2018-1738HIGH7.1IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive informatio...
CVE-2018-0052HIGH7.2If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can o...
CVE-2018-0051HIGH7.5A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allow...
CVE-2018-0050HIGH7.5An error handling vulnerability in Routing Protocols Daemon (RPD) of Juniper Networks Junos OS allows an attacker to cau...
CVE-2018-0049HIGH7.5A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to...
CVE-2018-0048HIGH7.5A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network b...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now