2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-4935HIGH8.8Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp...
CVE-2018-4932HIGH8.8Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Use-After-Free vulnerability. Successful exploita...
CVE-2018-4920HIGH8.8Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable type confusion vulnerability. Successful exploita...
CVE-2018-4919HIGH8.8Adobe Flash Player versions 28.0.0.161 and earlier have an exploitable use after free vulnerability. Successful exploita...
CVE-2018-11237HIGH7.8An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier m...
CVE-2018-5256HIGH7.5CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes ...
CVE-2018-1462HIGH7.6IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,...
CVE-2018-1438HIGH7.5IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,...
CVE-2018-1434HIGH8.8IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,...
CVE-2018-1433HIGH7.5IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1,...
CVE-2018-1111HIGH7.5DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in ...
CVE-2018-7160HIGH8.8The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remo...
CVE-2018-7158HIGH7.5The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) ve...
CVE-2018-0279HIGH8.8A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could a...
CVE-2018-1087HIGH8kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnera...
CVE-2018-10990HIGH8On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state ...
CVE-2018-1259HIGH7.5Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or e...
CVE-2018-1258HIGH8.8Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization b...
CVE-2018-8914HIGH7.3SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote att...
CVE-2018-8174HIGH7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows...
CVE-2018-8120HIGH7An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2018-0824HIGH8.8A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized ...
CVE-2018-1089HIGH7.5389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needi...
CVE-2018-1000168HIGH7.5nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC fr...
CVE-2018-1256HIGH8.1Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers th...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now