2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11801 | — | — | 5.2% | Jun 11, 2019 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que... |
| CVE-2018-11800 | — | — | 5.2% | Jun 11, 2019 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a que... |
| CVE-2018-20356 | — | — | 3.6% | Jun 10, 2019 | An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mon... |
| CVE-2018-20355 | — | — | 3.6% | Jun 10, 2019 | An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mo... |
| CVE-2018-20354 | — | — | 3.6% | Jun 10, 2019 | An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data functio... |
| CVE-2018-20353 | — | — | 3.6% | Jun 10, 2019 | An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data func... |
| CVE-2018-20352 | — | — | 2.7% | Jun 10, 2019 | Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Lib... |
| CVE-2018-10703 | — | — | 2.6% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script... |
| CVE-2018-10702 | HIGH | 8.8 | 5.3% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script... |
| CVE-2018-10701 | — | — | 2.6% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script... |
| CVE-2018-10700 | — | — | 39.3% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the... |
| CVE-2018-10699 | — | — | 1.9% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that ... |
| CVE-2018-10698 | CRITICAL | 9.8 | 2.3% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This... |
| CVE-2018-10697 | HIGH | 8.8 | 3.7% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administ... |
| CVE-2018-10696 | — | — | 1.1% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to ... |
| CVE-2018-10695 | — | — | 3.4% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send... |
| CVE-2018-10694 | HIGH | 8.1 | 0.8% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not ... |
| CVE-2018-10693 | — | — | 2.6% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execu... |
| CVE-2018-10692 | — | — | 1.3% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. ... |
| CVE-2018-10691 | — | — | 2.4% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log ... |
| CVE-2018-10690 | HIGH | 8.1 | 1.5% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insec... |
| CVE-2018-19999 | — | — | 0.6% | Jun 7, 2019 | The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local... |
| CVE-2018-19860 | — | — | 1.0% | Jun 7, 2019 | Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecif... |
| CVE-2018-19802 | — | — | 2.2% | Jun 7, 2019 | aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference. |
| CVE-2018-19801 | — | — | 2.1% | Jun 7, 2019 | aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now