2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1167This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player...
CVE-2018-1035A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Win...
CVE-2018-10204PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service. When co...
CVE-2018-10194The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.2...
CVE-2018-10110D-Link DIR-615 T1 devices allow XSS via the Add User feature.
CVE-2018-8840A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch M...
CVE-2018-7762A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon M340, Modicon Premiu...
CVE-2018-7761A vulnerability exists in the HTTP request parser in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum...
CVE-2018-7760An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC,...
CVE-2018-7759A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNO...
CVE-2018-7758A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet b...
CVE-2018-7246A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Managem...
CVE-2018-7245An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse inst...
CVE-2018-7244An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse inst...
CVE-2018-7243An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse instal...
CVE-2018-7242Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200...
CVE-2018-7241Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 control...
CVE-2018-7240A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could ...
CVE-2018-1325In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on di...
CVE-2018-1000167OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Functi...
CVE-2018-1000165LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in...
CVE-2018-1000164gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "...
CVE-2018-1000163Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can resul...
CVE-2018-1000162Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping ...
CVE-2018-1000161nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now