2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-15535/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname ...
CVE-2018-15499GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condi...
CVE-2018-15120MEDIUM6.5libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denia...
CVE-2018-14600An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as sign...
CVE-2018-14599CRITICAL9.8An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-on...
CVE-2018-14598An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in ...
CVE-2018-11065LOW2.7The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x pr...
CVE-2018-11061CRITICAL9.1RSA NetWitness Platform versions prior to 11.1.0.2 and RSA Security Analytics versions prior to 10.6.6 are vulnerable to...
CVE-2018-11749When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext t...
CVE-2018-1755MEDIUM5.9IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information, caused by incorr...
CVE-2018-1722CRITICAL10IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control...
CVE-2018-1699MEDIUM6.3IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to SQL injection. A remote attacker could send specially-cra...
CVE-2018-3909HIGH8.6An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET...
CVE-2018-3907CRITICAL10An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET...
CVE-2018-15822HIGH7.5The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, le...
CVE-2018-3911HIGH8.6An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 -...
CVE-2018-3880CRITICAL9.9An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of vide...
CVE-2018-3872CRITICAL9.9An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-3866CRITICAL9.9An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsun...
CVE-2018-3856CRITICAL9.9An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 -...
CVE-2018-15809AccuPOS 2017.8 is installed with the insecure "Authenticated Users: Modify" permission for files within the installation...
CVE-2018-15808POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM...
CVE-2018-15807POSIM EVO 15.13 for Windows includes an "Emergency Override" administrative account that may be accessed through POSIM's...
CVE-2018-6558The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values...
CVE-2018-14797HIGH7.8Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the se...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now