2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-15748On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware ...
CVE-2018-3833HIGH7.5An exploitable firmware downgrade vulnerability exists in Insteon Hub running firmware version 1013. The firmware upgrad...
CVE-2018-3832CRITICAL9An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows...
CVE-2018-15685GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindow...
CVE-2018-11758This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler...
CVE-2018-14801In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both t...
CVE-2018-14799In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device d...
CVE-2018-14789MEDIUM6.7In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an...
CVE-2018-14787HIGH7.8In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an...
CVE-2018-5238Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerabil...
CVE-2018-5235Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue tha...
CVE-2018-10919MEDIUM4.3The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access contro...
CVE-2018-10918MEDIUM5.2A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An auth...
CVE-2018-10858MEDIUM4.3A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malici...
CVE-2018-1140MEDIUM6.5A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker ...
CVE-2018-1139HIGH8.1A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 ...
CVE-2018-10884HIGH8.8Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authenticati...
CVE-2018-11776HIGH8.1Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN...
CVE-2018-10846MEDIUM5.6A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was fou...
CVE-2018-10845MEDIUM5.9It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote atta...
CVE-2018-10844MEDIUM5.9It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote atta...
CVE-2018-1599MEDIUM5.4IBM API Connect 5.0.0.0 through 5.0.8.3 could allow a remote attacker to hijack the clicking action of the victim. By pe...
CVE-2018-15672Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11207. Reason: This candidate is a reservation ...
CVE-2018-15671An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5...
CVE-2018-15670An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolic...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now