2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10840MEDIUM6.6Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An at...
CVE-2018-1046HIGH7.8pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS ...
CVE-2018-10886Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate is not about any specific ...
CVE-2018-14326In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom...
CVE-2018-14325In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
CVE-2018-14324The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin ...
CVE-2018-10859MEDIUM5.9git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could ...
CVE-2018-5239Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit. In this type of circumstance, the exploit ca...
CVE-2018-0385HIGH7.5A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower Syst...
CVE-2018-0384A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attack...
CVE-2018-0383A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attack...
CVE-2018-0370A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack...
CVE-2018-0369A vulnerability in the reassembly logic for fragmented IPv4 packets of Cisco StarOS running on virtual platforms could a...
CVE-2018-0368A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to acces...
CVE-2018-0366A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticat...
CVE-2018-0361ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively smal...
CVE-2018-0360ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor fil...
CVE-2018-0341A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11....
CVE-2018-13981The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code ...
CVE-2018-13980MEDIUM5.5The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos...
CVE-2018-11717An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a contex...
CVE-2018-11716An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to al...
CVE-2018-5229The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remot...
CVE-2018-14071The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.
CVE-2018-13387The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5,...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now