2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-10873HIGH8.3A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages l...
CVE-2018-1712HIGH8.6IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, us...
CVE-2018-0427HIGH8.8A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authentic...
CVE-2018-0418HIGH8.6A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services ...
CVE-2018-0409HIGH7.5A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) ...
CVE-2018-8414HIGH8.8A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows ...
CVE-2018-8406HIGH7.8An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje...
CVE-2018-8405HIGH7.8An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje...
CVE-2018-8375HIGH7.8A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2018-8373HIGH7.5A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2018-3615HIGH7.3Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow u...
CVE-2018-2446HIGH7.5Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensi...
CVE-2018-10636HIGH8.8CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabili...
CVE-2018-15139HIGH8.8Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote ...
CVE-2018-3775HIGH8.8Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentia...
CVE-2018-11048HIGH8.1Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) v...
CVE-2018-10925HIGH8.1It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check auth...
CVE-2018-10915HIGH8.5A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its inter...
CVE-2018-15133HIGH8.1In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri...
CVE-2018-11561HIGH7.5An integer overflow in the unprotected distributeToken function of a smart contract implementation for EETHER (EETHER), ...
CVE-2018-12408HIGH7.5The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix Busines...
CVE-2018-5390HIGH7.5Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queu...
CVE-2018-14716HIGH7.5A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques...
CVE-2018-14576HIGH7.5The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow v...
CVE-2018-1524HIGH8.8IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now