2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-9276HIGH7.2An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra...
CVE-2018-10874HIGH7.8In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command w...
CVE-2018-13041HIGH7.5The mint function of a smart contract implementation for Link Platform (LNK), an Ethereum ERC20 token, has an integer ov...
CVE-2018-12997HIGH7.5Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Con...
CVE-2018-12923HIGH7.5BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request fo...
CVE-2018-12922HIGH7.5Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configU...
CVE-2018-12920HIGH7.5Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the...
CVE-2018-3841HIGH7.5A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x69). The vulnerability is pre...
CVE-2018-3840HIGH7.5A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is pre...
CVE-2018-12895HIGH8.8WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/...
CVE-2018-4845HIGH8.8A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All vers...
CVE-2018-1000535HIGH7.5lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module tha...
CVE-2018-1000518HIGH7.5aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vuln...
CVE-2018-1000500HIGH8.1Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbi...
CVE-2018-0598HIGH7.8Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows ...
CVE-2018-11040HIGH7.5Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web app...
CVE-2018-12613HIGH8.8An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute...
CVE-2018-12617HIGH7.5qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h...
CVE-2018-0358HIGH7.5A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could ...
CVE-2018-0337HIGH7.8A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local...
CVE-2018-0313HIGH8.8A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a ma...
CVE-2018-0306HIGH7.8A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a comm...
CVE-2018-0302HIGH7.8A vulnerability in the CLI parser of Cisco FXOS Software and Cisco UCS Fabric Interconnect Software could allow an authe...
CVE-2018-0307HIGH7.8A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-inj...
CVE-2018-5428HIGH8.8The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contain...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now