2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0027HIGH7.5Receipt of a crafted or malformed RSVP PATH message may cause the routing protocol daemon (RPD) to hang or crash. When R...
CVE-2018-0026MEDIUM4.7After Junos OS device reboot or upgrade, the stateless firewall filter configuration may not take effect. This issue can...
CVE-2018-0025MEDIUM6.1When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authent...
CVE-2018-0024HIGH7.8An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated u...
CVE-2018-10635In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbi...
CVE-2018-10633Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow a...
CVE-2018-10232MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows...
CVE-2018-10231Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote...
CVE-2018-3936HIGH8.8In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft ...
CVE-2018-3933HIGH8.8An exploitable out-of-bounds write exists in the Microsoft Word document conversion functionality of the Antenna House O...
CVE-2018-3932HIGH8.8An exploitable stack-based buffer overflow exists in the Microsoft Word document conversion functionality of the Antenna...
CVE-2018-3931HIGH7.8In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft ...
CVE-2018-3930HIGH7.8In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft ...
CVE-2018-3929HIGH7.8An exploitable heap corruption exists in the PowerPoint document conversion functionality of the Antenna House Office Se...
CVE-2018-13989Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable...
CVE-2018-11529VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arb...
CVE-2018-10197There is a time-based blind SQL injection vulnerability in the Access Manager component before 9.18.040 and 10.x before ...
CVE-2018-8007Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of adm...
CVE-2018-0500Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that mig...
CVE-2018-13879A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, t...
CVE-2018-13878An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a u...
CVE-2018-8356A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certif...
CVE-2018-8327CRITICAL9.8A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code ...
CVE-2018-8326A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Feder...
CVE-2018-8325An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now