2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-1710HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffe...
CVE-2018-14645HIGH7.5A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read acc...
CVE-2018-6505HIGH7.5A potential Unauthenticated File Download vulnerability has been identified in ArcSight Management Center (ArcMC) in all...
CVE-2018-6504HIGH8.8A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in...
CVE-2018-6500HIGH7.5A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all ...
CVE-2018-3865HIGH8.8An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsu...
CVE-2018-3864HIGH8.8An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsu...
CVE-2018-3831HIGH8.8Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secre...
CVE-2018-3827HIGH8.1A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) pl...
CVE-2018-17182HIGH7.8An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles ...
CVE-2018-17144HIGH7.5Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16....
CVE-2018-6690HIGH7.1Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and ...
CVE-2018-13982HIGH7.5Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insuff...
CVE-2018-11071HIGH7.5Dell EMC Isilon OneFS versions 7.1.1.x, 7.2.1.x, 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 and Dell EMC IsilonS...
CVE-2018-14631HIGH8.8moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently fil...
CVE-2018-14630HIGH8.8moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional re...
CVE-2018-1223HIGH8.8Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to applic...
CVE-2018-17143HIGH7.5The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a ...
CVE-2018-17142HIGH7.5The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "pani...
CVE-2018-17095HIGH8.8An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3...
CVE-2018-17075HIGH7.5The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: ...
CVE-2018-14638HIGH7.5A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function ...
CVE-2018-8440HIGH7.8An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A...
CVE-2018-8409HIGH7.5A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines ...
CVE-2018-16981HIGH8.8stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__o...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now