2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-10905HIGH7.8CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. ...
CVE-2018-10604HIGH8.8SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modific...
CVE-2018-1999002HIGH7.5A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor...
CVE-2018-1999001HIGH8.8A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in U...
CVE-2018-6683HIGH7.4Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for ...
CVE-2018-10869HIGH7.5redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker...
CVE-2018-3871HIGH7.8An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially cra...
CVE-2018-3870HIGH7.8An exploitable out-of-bounds write exists in the PCX parsing functionality of Canvas Draw version 4.0.0. A specially cra...
CVE-2018-3860HIGH7.8An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially cr...
CVE-2018-3859HIGH7.8An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially cr...
CVE-2018-3858HIGH7.8An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted ...
CVE-2018-3857HIGH7.8An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted ...
CVE-2018-0387HIGH8.8A vulnerability in Cisco Webex Teams (for Windows and macOS) could allow an unauthenticated, remote attacker to execute ...
CVE-2018-0348HIGH7.2A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrar...
CVE-2018-0345HIGH8.8A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, ...
CVE-2018-10877HIGH7.3Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating...
CVE-2018-3064HIGH7.1Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected...
CVE-2018-2964HIGH8.3Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte...
CVE-2018-2942HIGH8.3Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affect...
CVE-2018-2941HIGH8.3Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected ar...
CVE-2018-14363HIGH7.5An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have u...
CVE-2018-14337HIGH7.5The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leadi...
CVE-2018-1046HIGH7.8pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS ...
CVE-2018-0385HIGH7.5A vulnerability in the detection engine parsing of Security Socket Layer (SSL) protocol packets for Cisco Firepower Syst...
CVE-2018-10875HIGH7.8A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it poin...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now