2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-10841HIGH8.8glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could u...
CVE-2018-12594HIGH7.5Reliable Controls MACH-ProWebCom 7.80 devices allow remote attackers to obtain sensitive information via a direct reques...
CVE-2018-1132HIGH7.5A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) wi...
CVE-2018-12590HIGH7.2Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability du...
CVE-2018-11116HIGH8.8OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authentic...
CVE-2018-10811HIGH7.5strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
CVE-2018-12565HIGH8.8An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() wh...
CVE-2018-1060HIGH7.5python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib...
CVE-2018-6497HIGH8.8Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20,...
CVE-2018-6496HIGH8.8Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, ...
CVE-2018-1460HIGH8.4IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writa...
CVE-2018-7167HIGH7.5Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Servic...
CVE-2018-7164HIGH7.5Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases...
CVE-2018-7162HIGH7.5All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service ...
CVE-2018-7161HIGH7.5All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of se...
CVE-2018-11806HIGH8.2m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
CVE-2018-1431HIGH7.4A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attac...
CVE-2018-5432HIGH8The TIBCO Administrator server component of of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO...
CVE-2018-2425HIGH8.4Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access informati...
CVE-2018-12249HIGH7.5An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject...
CVE-2018-0732HIGH7.5During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime v...
CVE-2018-12233HIGH7.8In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be trigg...
CVE-2018-6961HIGH8.1VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U...
CVE-2018-12020HIGH7.5mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allo...
CVE-2018-4233HIGH8.8An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now