2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16131The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0....
CVE-2018-14622HIGH7.5A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt...
CVE-2018-14621MEDIUM5.3An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than s...
CVE-2018-10936HIGH8.1A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t...
CVE-2018-14619HIGH7.8A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was bei...
CVE-2018-14317This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5...
CVE-2018-11616This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2....
CVE-2018-11615This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authenticatio...
CVE-2018-16158Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different cus...
CVE-2018-16142PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f f...
CVE-2018-16141ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileControl...
CVE-2018-16140A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the begi...
CVE-2018-16058In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was ad...
CVE-2018-16057HIGH7.5In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed...
CVE-2018-16056In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash...
CVE-2018-16134Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
CVE-2018-16133Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
CVE-2018-16132The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to chec...
CVE-2018-16115Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error. A random number g...
CVE-2018-7792HIGH7.5A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all ref...
CVE-2018-7791CRITICAL9.8A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all ref...
CVE-2018-7790CRITICAL9.8An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all v...
CVE-2018-7795MEDIUM5.4A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) pr...
CVE-2018-7789HIGH7.5An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 produc...
CVE-2018-12240MEDIUM5.9The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now