2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-1373HIGH7.5IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a r...
CVE-2018-1058HIGH8.8A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker wit...
CVE-2018-1170HIGH8.8This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installa...
CVE-2018-7550HIGH8.8The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute a...
CVE-2018-7480HIGH7.8The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial...
CVE-2018-7421HIGH7.5In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in...
CVE-2018-6488HIGH8.1Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could...
CVE-2018-1417HIGH8.1Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code r...
CVE-2018-0139HIGH8.6A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice...
CVE-2018-7311HIGH8.8PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability. The software installs a privileged h...
CVE-2018-5716HIGH8.1An issue was discovered in Reprise License Manager 11.0. This vulnerability is a Path Traversal where the attacker, by c...
CVE-2018-1165HIGH7This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-2...
CVE-2018-5379HIGH7.5The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE messa...
CVE-2018-5378HIGH7.1The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer...
CVE-2018-7206HIGH8.8An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When usi...
CVE-2018-6218HIGH7A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary c...
CVE-2018-7187HIGH8.8The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import pa...
CVE-2018-0842HIGH7Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, ...
CVE-2018-6910HIGH7.5DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/in...
CVE-2018-6954HIGH7.8systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local ...
CVE-2018-6860HIGH8.8Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a pr...
CVE-2018-1000052HIGH7.5fmtlib version prior to version 4.1.0 (before commit 0555cea5fc0bf890afe0071a558e44625a34ba85) contains a Memory corrupt...
CVE-2018-1000026HIGH7.7Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerab...
CVE-2018-4878HIGH7.8A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to ...
CVE-2018-6611HIGH8.8soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malfor...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now