2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-10597HIGH8.3IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monit...
CVE-2018-6662HIGH7.8Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to ga...
CVE-2018-3853HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software Foxit PDF Reader version 9...
CVE-2018-1600HIGH8.6IBM BigFix Platform 9.2 and 9.5 transmits sensitive or security-critical data in clear text in a communication channel t...
CVE-2018-11135HIGH8.8The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users...
CVE-2018-3734HIGH7.5stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malici...
CVE-2018-3733HIGH7.5crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url...
CVE-2018-11516HIGH8.8The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attacker...
CVE-2018-11506HIGH7.8The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a de...
CVE-2018-11490HIGH8.8The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0....
CVE-2018-11489HIGH8.8The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0....
CVE-2018-1565HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ...
CVE-2018-1544HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to ...
CVE-2018-1515HIGH7.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, c...
CVE-2018-1488HIGH8.4IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, whic...
CVE-2018-1125HIGH7.5procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FO...
CVE-2018-1122HIGH7.3procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset...
CVE-2018-1124HIGH7.8procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec ...
CVE-2018-6493HIGH8.8SQL Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation,...
CVE-2018-11329HIGH7.5The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attackers to take ...
CVE-2018-7687HIGH7.8The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevat...
CVE-2018-8012HIGH7.5No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, a...
CVE-2018-4942HIGH7.5Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe ...
CVE-2018-4938HIGH7.8Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecur...
CVE-2018-4937HIGH8.8Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now