2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0167HIGH8.8Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Ci...
CVE-2018-0165A vulnerability in the Internet Group Management Protocol (IGMP) packet-processing functionality of Cisco IOS XE Softwar...
CVE-2018-0164A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remo...
CVE-2018-0163MEDIUM6.5A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthen...
CVE-2018-0161MEDIUM6.3A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain mode...
CVE-2018-0160A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authentic...
CVE-2018-0159HIGH7.5A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and...
CVE-2018-0158HIGH8.6A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software co...
CVE-2018-0157HIGH8.6A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker...
CVE-2018-0156HIGH7.5A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica...
CVE-2018-0155HIGH8.6A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Swi...
CVE-2018-0154HIGH7.5A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Softwar...
CVE-2018-0152HIGH8.8A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a...
CVE-2018-0151CRITICAL9.8A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an...
CVE-2018-0150CRITICAL9.8A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running a...
CVE-2018-6608In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client informa...
CVE-2018-8885screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows...
CVE-2018-8820An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter...
CVE-2018-1064libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-57...
CVE-2018-7498In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confid...
CVE-2018-5451In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not ...
CVE-2018-9110CRITICAL9.1Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function...
CVE-2018-7676LOW3.9The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
CVE-2018-7674LOW2.1The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
CVE-2018-1142Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a speciall...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now