2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-3723defaults-deep node module before 0.2.4 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which...
CVE-2018-3722merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which al...
CVE-2018-3721MEDIUM6.5lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaults...
CVE-2018-3720HIGH8.8assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which a...
CVE-2018-3719HIGH8.8mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which al...
CVE-2018-3718MEDIUM5.3serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is ...
CVE-2018-3717MEDIUM5.4connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of...
CVE-2018-3716MEDIUM5.4simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
CVE-2018-3715MEDIUM6.5glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to ...
CVE-2018-3714MEDIUM6.5node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici...
CVE-2018-3713MEDIUM6.5angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilenam...
CVE-2018-3712serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and a...
CVE-2018-3711HIGH7.5Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: a...
CVE-2018-5850In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow...
CVE-2018-5846A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA...
CVE-2018-5845A race condition in drm_atomic_nonblocking_commit() in the display driver can potentially lead to a Use After Free scena...
CVE-2018-5841dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs ...
CVE-2018-5840Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android re...
CVE-2018-3852HIGH7.5An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A sp...
CVE-2018-3580Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in ...
CVE-2018-3578Type mismatch for ie_len can cause the WLAN driver to allocate less memory on the heap due to implicit casting leading t...
CVE-2018-3565While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for M...
CVE-2018-3562Buffer over -read can occur while processing a FILS authentication frame in all Android releases from CAF (Android for M...
CVE-2018-7510In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 41076000...
CVE-2018-1269Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now