2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-3834HIGH7.4An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013. The firmwa...
CVE-2018-10922HIGH7.5An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of se...
CVE-2018-1336HIGH7.5An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the d...
CVE-2018-3939HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1....
CVE-2018-3924HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version...
CVE-2018-3847HIGH8.8Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version...
CVE-2018-8034HIGH7.5The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions ...
CVE-2018-1595HIGH8.8IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary com...
CVE-2018-10897HIGH8.1A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote...
CVE-2018-10896HIGH7.1The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init'...
CVE-2018-3923HIGH7.8A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.54. A specially ...
CVE-2018-3922HIGH7.8A memory corruption vulnerability exists in the ANI-parsing functionality of Computerinsel Photoline 20.54. A specially ...
CVE-2018-3921HIGH7.8A memory corruption vulnerability exists in the PSD-parsing functionality of Computerinsel Photoline 20.54. A specially ...
CVE-2018-10898HIGH8.8A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director usin...
CVE-2018-10903HIGH7.5A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a m...
CVE-2018-13280HIGH7.4Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) ...
CVE-2018-14678HIGH7.8An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback en...
CVE-2018-1056HIGH7.8An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP fil...
CVE-2018-10878HIGH7.8A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of se...
CVE-2018-10901HIGH7.8A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the prev...
CVE-2018-10900HIGH7.8Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac...
CVE-2018-8090HIGH7.8Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bi...
CVE-2018-11060HIGH8.8RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authentic...
CVE-2018-11059HIGH8.2RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote authenticated malic...
CVE-2018-5387HIGH7.5Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now