2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-6599An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing att...
CVE-2018-6598An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices. Any app co-l...
CVE-2018-6597The Alcatel A30 device with a build fingerprint of TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys contains a hidde...
CVE-2018-15912An issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can ...
CVE-2018-15907Technicolor (formerly RCA) TC8305C devices allow remote attackers to cause a denial of service (networking outage) via a...
CVE-2018-15746MEDIUM5.5qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishand...
CVE-2018-15562CMS ISWEB 3.5.3 has XSS via the ordineRis, sezioneRicerca, or oggettiRicerca parameter to index.php.
CVE-2018-14768Various VIVOTEK FD8*, FD9*, FE9*, IB8*, IB9*, IP9*, IZ9*, MS9*, SD9*, and other devices before XXXXXX-VVTK-xx06a allow r...
CVE-2018-12710An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (whi...
CVE-2018-14805ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, ...
CVE-2018-558213Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-15727. Reason: This candidate is a reservation ...
CVE-2018-15727Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generat...
CVE-2018-8040Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to a...
CVE-2018-8022A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2....
CVE-2018-8005When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. T...
CVE-2018-8004There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache...
CVE-2018-5003Adobe Creative Cloud Desktop Application before 4.5.5.342 (installer) has an insecure library loading (dll hijacking) vu...
CVE-2018-1318Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects ve...
CVE-2018-12829Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful e...
CVE-2018-12828Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successf...
CVE-2018-12827Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t...
CVE-2018-12826Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t...
CVE-2018-12825Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to se...
CVE-2018-12824Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t...
CVE-2018-12811Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Succes...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now