2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-1441MEDIUM6.1IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.3 and 8.1.4) is vulnerable t...
CVE-2018-1050MEDIUM4.3All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is co...
CVE-2018-7858MEDIUM5.5Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged u...
CVE-2018-6311MEDIUM6.8One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UAR...
CVE-2018-7227MEDIUM5.3A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which ...
CVE-2018-1071MEDIUM5.5zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attac...
CVE-2018-1443MEDIUM5.9An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9....
CVE-2018-1442MEDIUM4.3IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.4) is vulnerable to cross-si...
CVE-2018-1387MEDIUM5.3IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensiti...
CVE-2018-0224MEDIUM6.7A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c...
CVE-2018-0217MEDIUM6.7A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c...
CVE-2018-0214MEDIUM5.3A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local atta...
CVE-2018-7473MEDIUM6.1Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attacke...
CVE-2018-1000117MEDIUM6.7Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in o...
CVE-2018-7170MEDIUM5.3ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key ...
CVE-2018-6529MEDIUM6.1XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR...
CVE-2018-6528MEDIUM6.1XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DI...
CVE-2018-6527MEDIUM6.1XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous version...
CVE-2018-5729MEDIUM4.7MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to c...
CVE-2018-1062MEDIUM5.3A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delet...
CVE-2018-7652MEDIUM6.1lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS.
CVE-2018-6490MEDIUM5.9Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could...
CVE-2018-2380MEDIUM6.6SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr...
CVE-2018-7557MEDIUM6.5The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denia...
CVE-2018-7547MEDIUM4.8lyadmin 1.x has XSS via the config[WEB_SITE_TITLE] parameter to the /admin.php?s=/admin/config/groupsave.html URI.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now