2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-25017CRITICAL9.8RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.
CVE-2018-25016CRITICAL9.8Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
CVE-2018-10867CRITICAL9.1Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an a...
CVE-2018-10866CRITICAL9.1It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it ...
CVE-2018-25014CRITICAL9.8A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
CVE-2018-25013CRITICAL9.1A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
CVE-2018-25012CRITICAL9.1A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
CVE-2018-25011CRITICAL9.8A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
CVE-2018-25010CRITICAL9.1A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
CVE-2018-25009CRITICAL9.1A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
CVE-2018-19945CRITICAL9.1A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitati...
CVE-2018-14067CRITICAL9.8Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command executio...
CVE-2018-15632CRITICAL9.1Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and ear...
CVE-2018-19025CRITICAL9.8In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on...
CVE-2018-17932CRITICAL9.8JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and c...
CVE-2018-19950CRITICAL9.8If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issu...
CVE-2018-19949CRITICAL9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has alre...
CVE-2018-4296CRITICAL9.8This issue is fixed in macOS Mojave 10.14. A permissions issue existed in DiskArbitration. This was addressed with addit...
CVE-2018-5353CRITICAL9.8The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execu...
CVE-2018-20432CRITICAL9.8D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows u...
CVE-2018-6446CRITICAL9.8A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log ...
CVE-2018-21268CRITICAL9.8The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host para...
CVE-2018-21251CRITICAL9.8An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name w...
CVE-2018-21246CRITICAL9.8Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lac...
CVE-2018-21245CRITICAL9.1Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now