2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0854A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device ...
CVE-2018-0824HIGH8.8A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized ...
CVE-2018-0765A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Co...
CVE-2018-10828An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri...
CVE-2018-10770download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a logi...
CVE-2018-10940The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers...
CVE-2018-1089HIGH7.5389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needi...
CVE-2018-1228Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-8912MEDIUM6.5Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remo...
CVE-2018-8911MEDIUM6.5Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote ...
CVE-2018-10683CRITICAL9.8An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm referenc...
CVE-2018-10682CRITICAL9.8An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TC...
CVE-2018-1119Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10184. Reason: This candidate is a reservation...
CVE-2018-10830In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv...
CVE-2018-10184An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size set...
CVE-2018-10831Z-NOMP before 2018-04-05 has an incorrect Equihash solution verifier that allows attackers to spoof mining shares, as de...
CVE-2018-10827LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exi...
CVE-2018-10817Severalnines ClusterControl before 1.6.0-4699 allows XSS.
CVE-2018-10705The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire cont...
CVE-2018-6921In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to user...
CVE-2018-6920In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient...
CVE-2018-10812The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which...
CVE-2018-8897A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa...
CVE-2018-6511MEDIUM5.4A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i...
CVE-2018-6510MEDIUM5.4A cross-site scripting vulnerability in Puppet Enterprise Console of Puppet Enterprise allows a user to inject scripts i...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now