2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11801SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que...
CVE-2018-11800SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que...
CVE-2018-20356An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mon...
CVE-2018-20355An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mo...
CVE-2018-20354An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data functio...
CVE-2018-20353An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data func...
CVE-2018-20352Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Lib...
CVE-2018-10703An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script...
CVE-2018-10702HIGH8.8An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script...
CVE-2018-10701An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script...
CVE-2018-10700An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the...
CVE-2018-10699An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that ...
CVE-2018-10698CRITICAL9.8An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This...
CVE-2018-10697HIGH8.8An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administ...
CVE-2018-10696An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to ...
CVE-2018-10695An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send...
CVE-2018-10694HIGH8.1An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not ...
CVE-2018-10693An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execu...
CVE-2018-10692An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. ...
CVE-2018-10691An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log ...
CVE-2018-10690HIGH8.1An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insec...
CVE-2018-19999The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local...
CVE-2018-19860Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecif...
CVE-2018-19802aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.
CVE-2018-19801aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now