2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-12565HIGH8.8An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() wh...
CVE-2018-12564An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can f...
CVE-2018-12563An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-ser...
CVE-2018-12562An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wr...
CVE-2018-12561An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additio...
CVE-2018-12560An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be perform...
CVE-2018-12559An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mo...
CVE-2018-12557An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a ta...
CVE-2018-10623Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buf...
CVE-2018-10621Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer whe...
CVE-2018-10617Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer wher...
CVE-2018-9029An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL in...
CVE-2018-9028Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
CVE-2018-9027A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute ma...
CVE-2018-9026A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions wit...
CVE-2018-9025An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with s...
CVE-2018-9024An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a...
CVE-2018-9023An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary com...
CVE-2018-9022CRITICAL9.8An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec...
CVE-2018-9021CRITICAL9.8An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec...
CVE-2018-1333By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker ex...
CVE-2018-12534A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.
CVE-2018-12531An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into con...
CVE-2018-12530An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files vi...
CVE-2018-1153Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests whi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now