2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-5546HIGH7.8The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a ...
CVE-2018-10873HIGH8.3A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages l...
CVE-2018-15122An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it pos...
CVE-2018-14567libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafte...
CVE-2018-13446An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authenticat...
CVE-2018-13435An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication ...
CVE-2018-13434An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID)...
CVE-2018-12256admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious fil...
CVE-2018-11511The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability...
CVE-2018-11509ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat...
CVE-2018-1712HIGH8.6IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, us...
CVE-2018-10140The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to sh...
CVE-2018-10139The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier...
CVE-2018-11771MEDIUM5.5When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputSt...
CVE-2018-1715MEDIUM5.4IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to ...
CVE-2018-0428A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, ...
CVE-2018-0427HIGH8.8A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authentic...
CVE-2018-0419A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unaut...
CVE-2018-0418HIGH8.6A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services ...
CVE-2018-0415A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Smal...
CVE-2018-0412A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Smal...
CVE-2018-0410A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow a...
CVE-2018-0409HIGH7.5A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) ...
CVE-2018-0386A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker ...
CVE-2018-0367A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authentica...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now