2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-21029CRITICAL9.8systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name ...
CVE-2018-21027CRITICAL9.8Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled...
CVE-2018-21024CRITICAL9.8licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
CVE-2018-21025CRITICAL9.8In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrec...
CVE-2018-10105CRITICAL9.8tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).
CVE-2018-10103CRITICAL9.8tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).
CVE-2018-21018CRITICAL9.8Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
CVE-2018-7820CRITICAL9.8A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could c...
CVE-2018-7081CRITICAL9.8A remote code execution vulnerability is present in network-listening components in some versions of ArubaOS. An attacke...
CVE-2018-17200CRITICAL9.8The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via th...
CVE-2018-21013CRITICAL9.8The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator a...
CVE-2018-20961CRITICAL9.8In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/func...
CVE-2018-11307CRITICAL9.8An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a ga...
CVE-2018-17842CRITICAL9.8SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
CVE-2018-20469CRITICAL9.8An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to...
CVE-2018-6349CRITICAL9.8When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for ...
CVE-2018-20655CRITICAL9.8When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a st...
CVE-2018-10698CRITICAL9.8An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This...
CVE-2018-18571CRITICAL9.1An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 a...
CVE-2018-13379CRITICAL9.8An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5....
CVE-2018-7847CRITICAL9.8A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quant...
CVE-2018-7846CRITICAL9.8A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon ...
CVE-2018-7842CRITICAL9.8A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Mod...
CVE-2018-7841CRITICAL9.8A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code...
CVE-2018-14839CRITICAL9.8LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attac...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now