2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-3710HIGH7.8Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project impor...
CVE-2018-8822HIGH7.8Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through...
CVE-2018-1221HIGH8.1In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket reque...
CVE-2018-1195HIGH8.8In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 28...
CVE-2018-1171HIGH7This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-2...
CVE-2018-5476HIGH7.8A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.0...
CVE-2018-2402HIGH7.6In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more ...
CVE-2018-2398HIGH7.5Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restr...
CVE-2018-1437HIGH7.8IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to mul...
CVE-2018-1435HIGH7.8IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a ma...
CVE-2018-1386HIGH7.8IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with im...
CVE-2018-1057HIGH8.8On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modi...
CVE-2018-6312HIGH7.2A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15...
CVE-2018-7236HIGH8.1A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ...
CVE-2018-7235HIGH7.5A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ...
CVE-2018-7234HIGH7.5A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ...
CVE-2018-7230HIGH8.8A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Elect...
CVE-2018-0209HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X ...
CVE-2018-5452HIGH7.5A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Co...
CVE-2018-7746HIGH8.8An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/chann...
CVE-2018-7745HIGH7.5An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst...
CVE-2018-7720HIGH8.8A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/create...
CVE-2018-7185HIGH7.5The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by ...
CVE-2018-7712HIGH7.5The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cau...
CVE-2018-7560HIGH7.5index.js in the Anton Myshenin aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of S...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now