2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11765HIGH7.5In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets with...
CVE-2018-6449MEDIUM6.1Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could a...
CVE-2018-6448HIGH7.5A vulnerability in the management interface in Brocade Fabric OS Versions before Brocade Fabric OS v9.0.0 could allow a ...
CVE-2018-6447MEDIUM5.4A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0....
CVE-2018-10585HIGH7.5Pexip Infinity before 18 allows remote Denial of Service (XML parsing).
CVE-2018-10432HIGH7.5Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).
CVE-2018-20432CRITICAL9.8D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows u...
CVE-2018-19948MEDIUM6.5The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forge...
CVE-2018-19947MEDIUM6.5The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vul...
CVE-2018-19946MEDIUM5.9The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate val...
CVE-2018-17145HIGH7.5Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of m...
CVE-2018-17774MEDIUM6.8Ingenico Telium 2 POS terminals have an insecure NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
CVE-2018-17773MEDIUM6.8Ingenico Telium 2 POS terminals have a buffer overflow via SOCKET_TASK in the NTPT3 protocol. This is fixed in Telium 2 ...
CVE-2018-17772MEDIUM6.8Ingenico Telium 2 POS terminals allow arbitrary code execution via the TRACE protocol. This is fixed in Telium 2 SDK v9....
CVE-2018-17771MEDIUM6.6Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
CVE-2018-17770MEDIUM6.6Ingenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol. This is fixe...
CVE-2018-17769MEDIUM6.6Ingenico Telium 2 POS terminals have a buffer overflow via the 0x26 command of the NTPT3 protocol. This is fixed in Teli...
CVE-2018-17768MEDIUM6.8Ingenico Telium 2 POS terminals have an insecure TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
CVE-2018-17767MEDIUM6.8Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
CVE-2018-17766MEDIUM4.6Ingenico Telium 2 POS Telium2 OS allow bypass of file-reading restrictions via the NTPT3 protocol. This is fixed in Teli...
CVE-2018-17765MEDIUM6.8Ingenico Telium 2 POS terminals have undeclared TRACE protocol commands. This is fixed in Telium 2 SDK v9.32.03 patch N.
CVE-2018-13903HIGH8.1u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, S...
CVE-2018-12475MEDIUM5.4A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUS...
CVE-2018-1501HIGH7.5IBM Security Guardium 10.5, 10.6, and 11.0 could allow an unauthorized user to obtain sensitive information due to missi...
CVE-2018-1985MEDIUM4.4IBM Trusteer Rapport/Apex 3.6.1908.22 contains an unused legacy driver which could allow a user with administrator privi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now