2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8812 | — | — | — | May 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-15610. Reason: This candidate is a reservation d... |
| CVE-2018-7120 | — | — | 2.1% | May 10, 2019 | A security vulnerability in the HPE Virtual Connect SE 16Gb Fibre Channel Module for HPE Synergy running firmware 5.00.5... |
| CVE-2018-7119 | — | — | 0.3% | May 10, 2019 | A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version S... |
| CVE-2018-7084 | CRITICAL | 9.8 | 4.6% | May 10, 2019 | A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web i... |
| CVE-2018-7064 | — | — | 1.4% | May 10, 2019 | A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An at... |
| CVE-2018-7083 | — | — | 1.8% | May 10, 2019 | If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents... |
| CVE-2018-7082 | HIGH | 7.2 | 4.3% | May 10, 2019 | A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execu... |
| CVE-2018-1990 | MEDIUM | 5.3 | 2.3% | May 10, 2019 | IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration i... |
| CVE-2018-1790 | MEDIUM | 4.3 | 0.5% | May 10, 2019 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forg... |
| CVE-2018-20837 | — | — | 0.7% | May 9, 2019 | include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS. |
| CVE-2018-5409 | — | — | 1.1% | May 8, 2019 | The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code withou... |
| CVE-2018-5408 | — | — | 0.7% | May 8, 2019 | The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly va... |
| CVE-2018-6634 | — | — | 1.5% | May 7, 2019 | A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized user... |
| CVE-2018-6243 | — | — | 0.2% | May 7, 2019 | NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of vi... |
| CVE-2018-20503 | — | — | 3.9% | May 7, 2019 | Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter. |
| CVE-2018-2008 | MEDIUM | 4.3 | 1.3% | May 7, 2019 | IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that coul... |
| CVE-2018-2001 | MEDIUM | 4.3 | 0.5% | May 7, 2019 | IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which coul... |
| CVE-2018-19456 | — | — | 1.8% | May 7, 2019 | The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive in... |
| CVE-2018-14485 | — | — | 16.3% | May 7, 2019 | BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. |
| CVE-2018-14478 | — | — | 1.0% | May 7, 2019 | ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient... |
| CVE-2018-13994 | HIGH | 7.5 | 2.2% | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack... |
| CVE-2018-13993 | HIGH | 8.8 | 0.9% | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF. |
| CVE-2018-13992 | HIGH | 8.2 | 1.1% | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of... |
| CVE-2018-13991 | MEDIUM | 5.3 | 1.6% | May 7, 2019 | The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware image... |
| CVE-2018-20836 | HIGH | 8.1 | 5.1% | May 7, 2019 | An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_d... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now