2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1259HIGH7.5Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or e...
CVE-2018-1258HIGH8.8Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization b...
CVE-2018-1257MEDIUM6.5Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows a...
CVE-2018-7248MEDIUM5.3An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate...
CVE-2018-10580The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displ...
CVE-2018-10982An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly...
CVE-2018-3649DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and...
CVE-2018-3617Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3691. Reason: This candidate is a reservation ...
CVE-2018-3612Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate pri...
CVE-2018-1118LOW2.3Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and t...
CVE-2018-10981An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infi...
CVE-2018-1115CRITICAL9.1postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() func...
CVE-2018-10973An integer overflow in the transferMulti function of a smart contract implementation for KoreaShow, an Ethereum ERC20 to...
CVE-2018-10706An integer overflow in the transferMulti function of a smart contract implementation for Social Chain (SCA), an Ethereum...
CVE-2018-10977In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv...
CVE-2018-10976In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv...
CVE-2018-10975In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv...
CVE-2018-10974In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv...
CVE-2018-10972An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/p...
CVE-2018-10971An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote at...
CVE-2018-9849Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly proce...
CVE-2018-7941Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft spec...
CVE-2018-7940Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0...
CVE-2018-7933Huawei home gateway products HiRouter-CD20 and WS5200 with the versions before HiRouter-CD20-10 1.9.6 and the versions b...
CVE-2018-6254In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improp...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now