2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-0175HIGH8Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE So...
CVE-2018-0174HIGH8.6A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could ...
CVE-2018-0173HIGH8.6A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 inform...
CVE-2018-0172HIGH8.6A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could ...
CVE-2018-0170HIGH7.5A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remot...
CVE-2018-0167HIGH8.8Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Ci...
CVE-2018-0159HIGH7.5A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and...
CVE-2018-0158HIGH8.6A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software co...
CVE-2018-0157HIGH8.6A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker...
CVE-2018-0156HIGH7.5A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica...
CVE-2018-0155HIGH8.6A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Swi...
CVE-2018-0154HIGH7.5A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Softwar...
CVE-2018-0152HIGH8.8A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a...
CVE-2018-7195HIGH8.1Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail addre...
CVE-2018-1267HIGH8.1Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platfo...
CVE-2018-1266HIGH8.1Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabili...
CVE-2018-9010HIGH7.2Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via t...
CVE-2018-8969HIGH7.5An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via direct...
CVE-2018-8968HIGH7.5An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory tr...
CVE-2018-8966HIGH7.5An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as de...
CVE-2018-8965HIGH7.5An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory tr...
CVE-2018-1000137HIGH8.8I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can re...
CVE-2018-1448HIGH7.7IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability tha...
CVE-2018-1426HIGH7.4IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system...
CVE-2018-8905HIGH8.8In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF fi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now