2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12468CRITICAL9.1A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attack...
CVE-2018-0413A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2018-0411A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthentic...
CVE-2018-0408A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could ...
CVE-2018-0407A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could ...
CVE-2018-0406A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticat...
CVE-2018-0397A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthen...
CVE-2018-0391A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, ...
CVE-2018-3847HIGH8.8Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version...
CVE-2018-14777An issue was discovered in DataLife Engine (DLE) through 13.0. An attacker can use XSS (related to the /addnews.html and...
CVE-2018-8034HIGH7.5The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions ...
CVE-2018-10618Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke...
CVE-2018-1595HIGH8.8IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary com...
CVE-2018-10897HIGH8.1A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote...
CVE-2018-10896HIGH7.1The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init'...
CVE-2018-10894MEDIUM5.4It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A maliciou...
CVE-2018-3923HIGH7.8A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.54. A specially ...
CVE-2018-3922HIGH7.8A memory corruption vulnerability exists in the ANI-parsing functionality of Computerinsel Photoline 20.54. A specially ...
CVE-2018-3921HIGH7.8A memory corruption vulnerability exists in the PSD-parsing functionality of Computerinsel Photoline 20.54. A specially ...
CVE-2018-3672Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute...
CVE-2018-3671Escalation of privilege in Intel Saffron admin application before 11.4 allows an authenticated user to access unauthoriz...
CVE-2018-3670Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute...
CVE-2018-3666Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute...
CVE-2018-3663Escalation of privilege in Intel Saffron MemoryBase before 11.4 allows an authenticated user access to privileged inform...
CVE-2018-3662Escalation of privilege in Intel Saffron MemoryBase before version 11.4 potentially allows an authorized user of the Saf...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now