2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-6259NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an...
CVE-2018-6258NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during GameStream installation...
CVE-2018-6257NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled whe...
CVE-2018-11057MEDIUM5.9RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Tim...
CVE-2018-11056MEDIUM6.5RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5...
CVE-2018-11055MEDIUM5.5RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper...
CVE-2018-11054HIGH7.5RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use ma...
CVE-2018-3787HIGH7.5Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
CVE-2018-16278phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the ...
CVE-2018-16276HIGH7.8An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers cou...
CVE-2018-7685HIGH7.8The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the c...
CVE-2018-16275OPSWAT MetaDefender before v4.11.2 allows CSV injection.
CVE-2018-16239An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to ...
CVE-2018-16238An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to...
CVE-2018-16237An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.p...
CVE-2018-16236cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is ...
CVE-2018-16234MorningStar WhatWeb 0.4.9 has XSS via JSON report files.
CVE-2018-16233MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.
CVE-2018-16231Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daem...
CVE-2018-6499HIGH7.1Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2...
CVE-2018-6498HIGH8.8Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2...
CVE-2018-15364A Named Pipe Request Processing Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro OfficeScan XG (12...
CVE-2018-15363An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a ...
CVE-2018-10514A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow ...
CVE-2018-10513A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now