2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-15610HIGH7.3A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arb...
CVE-2018-3885HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re...
CVE-2018-3884HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re...
CVE-2018-3883HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re...
CVE-2018-3882HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re...
CVE-2018-10893HIGH7.6Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames....
CVE-2018-10853HIGH7A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrst...
CVE-2018-1571HIGH8.8IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sendi...
CVE-2018-3897HIGH8.8An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of S...
CVE-2018-3896HIGH8.8An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of S...
CVE-2018-15552HIGH7.5The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling...
CVE-2018-4010HIGH7.8An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A special...
CVE-2018-3952HIGH8.8An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafte...
CVE-2018-1789HIGH8.4IBM API Connect v2018.1.0 through v2018.3.4 could allow an attacker to send a specially crafted request to conduct a ser...
CVE-2018-1756HIGH7.5IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker co...
CVE-2018-5391HIGH7.5The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packet...
CVE-2018-1695HIGH7.3IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to con...
CVE-2018-14632HIGH7.7An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Contai...
CVE-2018-14624HIGH7.5A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the ...
CVE-2018-16552HIGH8.8MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs.
CVE-2018-14618HIGH7.5curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl...
CVE-2018-10929HIGH8.8A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw...
CVE-2018-10928HIGH8.8A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to...
CVE-2018-10927HIGH8.1A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw...
CVE-2018-10926HIGH8.8A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now