2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-16151HIGH7.5In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the R...
CVE-2018-17555HIGH7.5The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /s...
CVE-2018-8848HIGH7.5Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permi...
CVE-2018-10606HIGH8.8WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple heap-based buffer overflow vulnerabilities that can be exploit...
CVE-2018-10602HIGH8.8WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple stack-based buffer overflow vulnerabilities that can be exploi...
CVE-2018-1785HIGH7.5IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that co...
CVE-2018-1545HIGH7.5IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that co...
CVE-2018-14634HIGH7.8An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a...
CVE-2018-1669HIGH7.1IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15...
CVE-2018-1607HIGH7.1IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity...
CVE-2018-1588HIGH7.1IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to...
CVE-2018-15964HIGH7.5Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use ...
CVE-2018-14647HIGH7.5Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy...
CVE-2018-14633HIGH7A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a wa...
CVE-2018-6700HIGH7.8DLL Search Order Hijacking vulnerability in Microsoft Windows Client in McAfee True Key (TK) before 5.1.165 allows local...
CVE-2018-15615HIGH7.2A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract ...
CVE-2018-15613HIGH8.3A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could re...
CVE-2018-15612HIGH8.3A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add...
CVE-2018-14730HIGH7.5An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests i...
CVE-2018-3915HIGH8.2An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT...
CVE-2018-3914HIGH7.8An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT...
CVE-2018-3906HIGH8.2An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTT...
CVE-2018-3894HIGH8.8An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa...
CVE-2018-3876HIGH8.8An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung Sm...
CVE-2018-1711HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now