2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-8926HIGH8.8Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before...
CVE-2018-8925HIGH8.8Cross-site request forgery (CSRF) vulnerability in admin/user.php in Synology Photo Station before 6.8.5-3471 and before...
CVE-2018-1453HIGH8.8IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dang...
CVE-2018-3758HIGH8.8Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hostin...
CVE-2018-0338HIGH7.8A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allo...
CVE-2018-6670HIGH7.6External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated us...
CVE-2018-1547HIGH8IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on ...
CVE-2018-7689HIGH7.1Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed aut...
CVE-2018-7688HIGH7.1A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated ...
CVE-2018-0296HIGH7.5A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo...
CVE-2018-0274HIGH8.8A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote atta...
CVE-2018-0263HIGH7.4A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services runni...
CVE-2018-3737HIGH7.5sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
CVE-2018-3732HIGH7.5resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths wit...
CVE-2018-3731HIGH7.5public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a mal...
CVE-2018-3730HIGH7.5mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a m...
CVE-2018-3729HIGH7.5localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a ...
CVE-2018-3727HIGH7.5626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious ...
CVE-2018-3725HIGH7.5hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a maliciou...
CVE-2018-3720HIGH8.8assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which a...
CVE-2018-3719HIGH8.8mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which al...
CVE-2018-3711HIGH7.5Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: a...
CVE-2018-3852HIGH7.5An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A sp...
CVE-2018-1000194HIGH8.1A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFi...
CVE-2018-10601HIGH8.2IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monit...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now