2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-4878HIGH7.8A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to ...
CVE-2018-6611HIGH8.8soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malfor...
CVE-2018-6486HIGH7.3XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Se...
CVE-2018-6479HIGH7.5An issue was discovered on Netwave IP Camera devices. An unauthenticated attacker can crash a device by sending a POST r...
CVE-2018-0136HIGH8.6A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (...
CVE-2018-6195HIGH7.2admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPre...
CVE-2018-3835HIGH8.8An exploitable out of bounds write vulnerability exists in version 2.2 of the Per Face Texture mapping application known...
CVE-2018-6383HIGH8.8Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but ...
CVE-2018-1048HIGH7.5It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH ...
CVE-2018-6003HIGH7.5An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited rec...
CVE-2018-5968HIGH8.1FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o...
CVE-2018-5960HIGH8.8Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Catego...
CVE-2018-2725HIGH8.1Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Servic...
CVE-2018-2639HIGH8.3Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte...
CVE-2018-2638HIGH8.3Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte...
CVE-2018-2637HIGH7.4Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versi...
CVE-2018-2633HIGH8.3Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported vers...
CVE-2018-2627HIGH7.5Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected...
CVE-2018-2562HIGH7.1Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supported versions that ...
CVE-2018-5764HIGH7.5The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses,...
CVE-2018-5721HIGH8.8Stack-based buffer overflow in the ej_update_variables function in router/httpd/web.c on ASUS routers (when using softwa...
CVE-2018-5332HIGH7.8In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA ...
CVE-2018-0012HIGH7.8Junos Space is affected by a privilege escalation vulnerability that may allow a local authenticated attacker to gain ro...
CVE-2018-0005HIGH7.4QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forward traffic instead o...
CVE-2018-0002HIGH8.2On SRX Series and MX Series devices with a Service PIC with any ALG enabled, a crafted TCP/IP response packet processed ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now