2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18365——Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to dis...
CVE-2018-7118——A local access restriction bypass vulnerability was identified in HPE Service Pack for ProLiant (SPP) Bundled Software e...
CVE-2018-7117——A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out ...
CVE-2018-18507——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-20698——The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page wh...
CVE-2018-19586——Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered du...
CVE-2018-14894——CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file...
CVE-2018-19589——Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM pr...
CVE-2018-13366——An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial num...
CVE-2018-20341——WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an ...
CVE-2018-19006——OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulne...
CVE-2018-20816——An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 ...
CVE-2018-19282——Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by cra...
CVE-2018-18068——The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 co...
CVE-2018-20229——GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory...
CVE-2018-20449——The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain s...
CVE-2018-20222——XXE issue in Airsonic before 10.1.2 during parse.
CVE-2018-10244——Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code...
CVE-2018-10243——htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer ov...
CVE-2018-19981——Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retr...
CVE-2018-13918——kernel could return a received message length higher than expected, which leads to buffer overflow in a subsequent opera...
CVE-2018-11971——Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asse...
CVE-2018-11970——TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Ele...
CVE-2018-11966——Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon ...
CVE-2018-11958——Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon A...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now