2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-10843HIGH8.5source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9....
CVE-2018-9276HIGH7.2An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra...
CVE-2018-10874HIGH7.8In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command w...
CVE-2018-13041HIGH7.5The mint function of a smart contract implementation for Link Platform (LNK), an Ethereum ERC20 token, has an integer ov...
CVE-2018-12997HIGH7.5Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Con...
CVE-2018-12923HIGH7.5BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request fo...
CVE-2018-12922HIGH7.5Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configU...
CVE-2018-12920HIGH7.5Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the...
CVE-2018-3841HIGH7.5A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x69). The vulnerability is pre...
CVE-2018-3840HIGH7.5A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is pre...
CVE-2018-12895HIGH8.8WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/...
CVE-2018-4845HIGH8.8A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All vers...
CVE-2018-1000535HIGH7.5lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module tha...
CVE-2018-1000518HIGH7.5aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vuln...
CVE-2018-1000500HIGH8.1Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbi...
CVE-2018-0598HIGH7.8Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows ...
CVE-2018-11040HIGH7.5Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web app...
CVE-2018-12613HIGH8.8An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute...
CVE-2018-12617HIGH7.5qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h...
CVE-2018-0358HIGH7.5A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could ...
CVE-2018-0337HIGH7.8A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local...
CVE-2018-0313HIGH8.8A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a ma...
CVE-2018-0306HIGH7.8A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a comm...
CVE-2018-0302HIGH7.8A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authe...
CVE-2018-0307HIGH7.8A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-inj...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now