2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16460A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker co...
CVE-2018-16704An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possibl...
CVE-2018-16703A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple us...
CVE-2018-16667An issue was discovered in Contiki-NG through 4.1. There is a buffer over-read in lookup in os/storage/antelope/lvm.c wh...
CVE-2018-16666An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in next_string in os/storage/a...
CVE-2018-16665An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow while parsing AQL in lvm_shift_for_operato...
CVE-2018-16664An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow in lvm_set_type in os/storage/antelope/lvm...
CVE-2018-16663An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/stora...
CVE-2018-4010HIGH7.8An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A special...
CVE-2018-3952HIGH8.8An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafte...
CVE-2018-1789HIGH8.4IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a ser...
CVE-2018-1757MEDIUM5.3IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 could allow an attacker to obtain sensitive informat...
CVE-2018-1756HIGH7.5IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker co...
CVE-2018-1567CRITICAL9.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code thro...
CVE-2018-16658An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cd...
CVE-2018-16657In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation ...
CVE-2018-0663Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and ea...
CVE-2018-0662Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and ea...
CVE-2018-0661Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and ea...
CVE-2018-0660Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create ar...
CVE-2018-0659Directory traversal vulnerability in ver.2.8.4.0 and earlier and ver.3.3.0.0 and earlier allows an attacker to create or...
CVE-2018-0658Input validation issue in EC-CUBE Payment Module (2.12) version 3.5.23 and earlier, EC-CUBE Payment Module (2.11) versio...
CVE-2018-0657Cross-site scripting vulnerability in EC-CUBE Payment Module and GMO-PG Payment Module (PG Multi-Payment Service) for EC...
CVE-2018-0655Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitra...
CVE-2018-0654Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now