2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16496MEDIUM5.3In Versa Director, the un-authentication request found.
CVE-2018-16495HIGH8.8In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not change...
CVE-2018-16494HIGH8.8In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through in...
CVE-2018-10868HIGH7.5redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allo...
CVE-2018-10867CRITICAL9.1Files are accessible without restrictions from the /update/results page of redhat-certification 7 package, allowing an a...
CVE-2018-10866CRITICAL9.1It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it ...
CVE-2018-10865HIGH7.5It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it ...
CVE-2018-10863HIGH7.5It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /...
CVE-2018-25014CRITICAL9.8A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
CVE-2018-25013CRITICAL9.1A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
CVE-2018-25012CRITICAL9.1A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
CVE-2018-25011CRITICAL9.8A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
CVE-2018-25010CRITICAL9.1A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
CVE-2018-25009CRITICAL9.1A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
CVE-2018-25007MEDIUM4.3Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0...
CVE-2018-19942MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, t...
CVE-2018-25008MEDIUM5.9In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchroniz...
CVE-2018-1110HIGH7.5A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.
CVE-2018-1109MEDIUM5.3A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vuln...
CVE-2018-1107MEDIUM5.3It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON f...
CVE-2018-25004MEDIUM4.9A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain co...
CVE-2018-3633Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-10349Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2018-10348Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2018-10347Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now