2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10509A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh att...
CVE-2018-10508A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to eleva...
CVE-2018-10507A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or ...
CVE-2018-10470MEDIUM5.3Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllAr...
CVE-2018-5814In the Linux Kernel before version 4.16.11, 4.14.43, 4.9.102, and 4.4.133, multiple race condition errors when handling ...
CVE-2018-5803In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_ch...
CVE-2018-5718Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft Sy...
CVE-2018-2428MEDIUM5.3Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. S...
CVE-2018-2425HIGH8.4Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access informati...
CVE-2018-2424CRITICAL9.8SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided Java...
CVE-2018-1103MEDIUM6.1Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An att...
CVE-2018-12249HIGH7.5An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject...
CVE-2018-12248An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/...
CVE-2018-12247An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class, related to certain .clone usag...
CVE-2018-1075MEDIUM5ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engi...
CVE-2018-1070MEDIUM6.5routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which c...
CVE-2018-0732HIGH7.5During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime v...
CVE-2018-12233HIGH7.8In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be trigg...
CVE-2018-12232In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where ...
CVE-2018-12229Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 al...
CVE-2018-12228An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the clien...
CVE-2018-12227An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Cert...
CVE-2018-6968The VMware AirWatch Agent for Android prior to 8.2 and AirWatch Agent for Windows Mobile prior to 6.5.2 contain a remote...
CVE-2018-6961HIGH8.1VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U...
CVE-2018-5185Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now