2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-3626Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible...
CVE-2018-5768A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted ...
CVE-2018-1141When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce se...
CVE-2018-8822HIGH7.8Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through...
CVE-2018-5438Philips ISCV application prior to version 2.3.0 has an insufficient session expiration vulnerability where an attacker c...
CVE-2018-1322An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupporte...
CVE-2018-1321An administrator with report and template entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and un...
CVE-2018-1294If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounc...
CVE-2018-8088CRITICAL9.8org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass int...
CVE-2018-7511In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer...
CVE-2018-5770An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, ...
CVE-2018-5717Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to u...
CVE-2018-4844MEDIUM6.7A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI fo...
CVE-2018-4843MEDIUM6.5A vulnerability has been identified in SIMATIC S7-400 CPU 414-3 PN/DP V7 (All versions < V7.0.3), SIMATIC S7-400 CPU 4...
CVE-2018-1000135GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver ...
CVE-2018-8821windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafte...
CVE-2018-8815Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in...
CVE-2018-8811Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow...
CVE-2018-8810In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote atta...
CVE-2018-8809In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers co...
CVE-2018-8808In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers co...
CVE-2018-8807In libming 0.4.8, these is a use-after-free in the function decompileCALLFUNCTION of decompile.c. Remote attackers could...
CVE-2018-8806In libming 0.4.8, there is a use-after-free in the decompileArithmeticOp function of decompile.c. Remote attackers could...
CVE-2018-8805Yxcms building system (compatible cell phone) v1.4.7 has XSS via the content parameter to protected\apps\default\view\de...
CVE-2018-8804WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCo...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now