2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-4029CRITICAL9.8An exploitable code execution vulnerability exists in the HTTP request-parsing function of the NT9665X Chipset firmware ...
CVE-2018-4023CRITICAL9.8An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, ...
CVE-2018-4018CRITICAL9.8An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware, running on Anker Roav A1 Dashcam ve...
CVE-2018-4014CRITICAL9.8An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SW...
CVE-2018-7084CRITICAL9.8A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web i...
CVE-2018-16988CRITICAL9.8An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak pa...
CVE-2018-16530CRITICAL9.8A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and p...
CVE-2018-16529CRITICAL9.8A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be use...
CVE-2018-4003CRITICAL9.8An exploitable heap overflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003...
CVE-2018-3985CRITICAL9.8An exploitable double free vulnerability exists in the mdnscap binary of the CUJO Smart Firewall. When parsing mDNS pack...
CVE-2018-4059CRITICAL9.8An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version ...
CVE-2018-20525CRITICAL9.1Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
CVE-2018-19365CRITICAL9.1The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via ...
CVE-2018-19276CRITICAL9.8OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use...
CVE-2018-20177CRITICAL9.8rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in t...
CVE-2018-17988CRITICAL9.8LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.
CVE-2018-18815CRITICAL10The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition...
CVE-2018-19725CRITICAL9.8Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and...
CVE-2018-20033CRITICAL9.8A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and e...
CVE-2018-20784CRITICAL9.8In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denia...
CVE-2018-13792CRITICAL9.8Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release...
CVE-2018-3991CRITICAL10An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, ve...
CVE-2018-3990CRITICAL9.3An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKe...
CVE-2018-8800CRITICAL9.8rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that...
CVE-2018-8797CRITICAL9.8rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that resul...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now