2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18365Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to dis...
CVE-2018-7118A local access restriction bypass vulnerability was identified in HPE Service Pack for ProLiant (SPP) Bundled Software e...
CVE-2018-7117A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out ...
CVE-2018-18507Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-20698The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page wh...
CVE-2018-19586Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered du...
CVE-2018-14894CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file...
CVE-2018-19589Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM pr...
CVE-2018-13366An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial num...
CVE-2018-20341WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an ...
CVE-2018-19006OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulne...
CVE-2018-20816An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 ...
CVE-2018-19282Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by cra...
CVE-2018-18068The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 co...
CVE-2018-20229GitLab Community and Enterprise Edition before 11.3.14, 11.4.x before 11.4.12, and 11.5.x before 11.5.5 allows Directory...
CVE-2018-20449The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain s...
CVE-2018-20222XXE issue in Airsonic before 10.1.2 during parse.
CVE-2018-10244Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code...
CVE-2018-10243htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer ov...
CVE-2018-19981Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retr...
CVE-2018-13918kernel could return a received message length higher than expected, which leads to buffer overflow in a subsequent opera...
CVE-2018-11971Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asse...
CVE-2018-11970TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Ele...
CVE-2018-11966Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon ...
CVE-2018-11958Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon A...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now