2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18625MEDIUM6.1Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an...
CVE-2018-18624MEDIUM6.1Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an ...
CVE-2018-18623MEDIUM6.1Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for ...
CVE-2018-21234CRITICAL9.8Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
CVE-2018-10756HIGH7.8Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of ser...
CVE-2018-1285CRITICAL9.8Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. Thi...
CVE-2018-20225HIGH7.8An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if t...
CVE-2018-5484Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2018-5491Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2018-5480Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2018-5493HIGH7.5ATTO FibreBridge 7500N firmware versions prior to 2.90 are susceptible to a vulnerability which allows an unauthenticate...
CVE-2018-8956MEDIUM5.3ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchron...
CVE-2018-21233MEDIUM6.5TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the co...
CVE-2018-21232MEDIUM5.5re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags.
CVE-2018-21226HIGH8.8Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before...
CVE-2018-21225MEDIUM6.8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000 before 1.0.1.60, ...
CVE-2018-21224HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....
CVE-2018-21223HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....
CVE-2018-21222HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....
CVE-2018-21221HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....
CVE-2018-21220HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....
CVE-2018-21219HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....
CVE-2018-21218HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....
CVE-2018-21217HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....
CVE-2018-21216HIGH8.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0....

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now