2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19800 | — | — | 2.2% | Jun 7, 2019 | aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo. |
| CVE-2018-19465 | — | — | 0.8% | Jun 7, 2019 | Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php ... |
| CVE-2018-19462 | — | — | 2.2% | Jun 7, 2019 | admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that... |
| CVE-2018-19461 | — | — | 0.9% | Jun 7, 2019 | admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php. |
| CVE-2018-19452 | — | — | 2.9% | Jun 7, 2019 | A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF ... |
| CVE-2018-19451 | — | — | 2.7% | Jun 7, 2019 | A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when... |
| CVE-2018-5264 | — | — | 1.5% | Jun 7, 2019 | Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free ti... |
| CVE-2018-20523 | MEDIUM | 5.3 | 10.0% | Jun 7, 2019 | Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider ... |
| CVE-2018-20135 | — | — | 1.8% | Jun 7, 2019 | Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of appl... |
| CVE-2018-20091 | — | — | 1.0% | Jun 7, 2019 | An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow... |
| CVE-2018-20014 | — | — | 1.4% | Jun 7, 2019 | In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin... |
| CVE-2018-6185 | — | — | 0.5% | Jun 7, 2019 | In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undel... |
| CVE-2018-5798 | — | — | 0.7% | Jun 7, 2019 | This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager. |
| CVE-2018-5265 | — | — | 3.0% | Jun 7, 2019 | Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credential... |
| CVE-2018-9839 | — | — | 1.2% | Jun 6, 2019 | An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying... |
| CVE-2018-8047 | — | — | 1.3% | Jun 6, 2019 | vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and proba... |
| CVE-2018-2028 | MEDIUM | 6.5 | 0.8% | Jun 6, 2019 | IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which ... |
| CVE-2018-10171 | — | — | 1.8% | Jun 5, 2019 | Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyz... |
| CVE-2018-7125 | — | — | 1.3% | Jun 5, 2019 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio... |
| CVE-2018-7124 | — | — | 8.0% | Jun 5, 2019 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio... |
| CVE-2018-7123 | — | — | 57.7% | Jun 5, 2019 | A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ver... |
| CVE-2018-7122 | — | — | 1.7% | Jun 5, 2019 | A remote disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier ... |
| CVE-2018-7121 | — | — | 7.6% | Jun 5, 2019 | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than versio... |
| CVE-2018-18571 | CRITICAL | 9.1 | 2.8% | Jun 5, 2019 | An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 a... |
| CVE-2018-13384 | — | — | 1.1% | Jun 4, 2019 | A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a r... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now