2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0353A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, re...
CVE-2018-0322A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authentic...
CVE-2018-0321A vulnerability in Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to acces...
CVE-2018-0320A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated...
CVE-2018-0319A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthe...
CVE-2018-0318A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenti...
CVE-2018-0317A vulnerability in the web interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remot...
CVE-2018-0316A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8...
CVE-2018-0315CRITICAL9.8A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software co...
CVE-2018-0296HIGH7.5A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo...
CVE-2018-0274HIGH8.8A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote atta...
CVE-2018-0263HIGH7.4A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services runni...
CVE-2018-3739https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in Do...
CVE-2018-3738MEDIUM5.5protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
CVE-2018-3737HIGH7.5sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
CVE-2018-3736Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3739. Reason: This candidate is a duplicate of...
CVE-2018-3735MEDIUM6.1bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
CVE-2018-3732HIGH7.5resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths wit...
CVE-2018-3731HIGH7.5public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a mal...
CVE-2018-3730HIGH7.5mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a m...
CVE-2018-3729HIGH7.5localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a ...
CVE-2018-3727HIGH7.5626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious ...
CVE-2018-3726MEDIUM6.1crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of f...
CVE-2018-3725HIGH7.5hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a maliciou...
CVE-2018-3724general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now