2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-1084HIGH7.5corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
CVE-2018-1079HIGH8.7pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The...
CVE-2018-1029HIGH7.8A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2018-1027HIGH7.8A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje...
CVE-2018-3888HIGH7.8A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ...
CVE-2018-3887HIGH7.8A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ...
CVE-2018-3886HIGH7.8A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially ...
CVE-2018-10054HIGH8.8H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can...
CVE-2018-1100HIGH7.8zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local ...
CVE-2018-0022HIGH7.5A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when ...
CVE-2018-0021HIGH8.8If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CA...
CVE-2018-0020HIGH7.5Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash...
CVE-2018-0018HIGH7.5On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to b...
CVE-2018-0017HIGH7.5A vulnerability in the Network Address Translation - Protocol Translation (NAT-PT) feature of Junos OS on SRX series dev...
CVE-2018-3839HIGH8.8An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer ...
CVE-2018-9989HIGH7.5ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that co...
CVE-2018-9988HIGH7.5ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() tha...
CVE-2018-2408HIGH7.3Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Laun...
CVE-2018-9331HIGH7.5An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory trave...
CVE-2018-1272HIGH7.5Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide c...
CVE-2018-1421HIGH7.1IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection...
CVE-2018-0986HIGH8.8A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci...
CVE-2018-9240HIGH7.5ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends ...
CVE-2018-6661HIGH7.8DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain...
CVE-2018-0177HIGH7.5A vulnerability in the IP Version 4 (IPv4) processing code of Cisco IOS XE Software running on Cisco Catalyst 3850 and C...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now