2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-10923HIGH8.1It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node...
CVE-2018-10911HIGH7.5A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacke...
CVE-2018-10907HIGH8.8It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc...
CVE-2018-10904HIGH8.8It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribu...
CVE-2018-16384HIGH7.5A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0...
CVE-2018-11054HIGH7.5RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use ma...
CVE-2018-3787HIGH7.5Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
CVE-2018-16276HIGH7.8An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers cou...
CVE-2018-7685HIGH7.8The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the c...
CVE-2018-6499HIGH7.1Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2...
CVE-2018-6498HIGH8.8Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2...
CVE-2018-13822HIGH7.5Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, all...
CVE-2018-14622HIGH7.5A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt...
CVE-2018-10936HIGH8.1A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t...
CVE-2018-14619HIGH7.8A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was bei...
CVE-2018-16057HIGH7.5In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed...
CVE-2018-7792HIGH7.5A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all ref...
CVE-2018-7789HIGH7.5An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 produc...
CVE-2018-3916HIGH7.8An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HT...
CVE-2018-3908HIGH7.5An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ET...
CVE-2018-3895HIGH8.8An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa...
CVE-2018-3918HIGH7.5An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20...
CVE-2018-3893HIGH8.8An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Sa...
CVE-2018-15877HIGH8.8The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta...
CVE-2018-11654HIGH7.5Information disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now