2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-8812Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-15610. Reason: This candidate is a reservation d...
CVE-2018-7120A security vulnerability in the HPE Virtual Connect SE 16Gb Fibre Channel Module for HPE Synergy running firmware 5.00.5...
CVE-2018-7119A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version S...
CVE-2018-7084CRITICAL9.8A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web i...
CVE-2018-7064A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An at...
CVE-2018-7083If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents...
CVE-2018-7082HIGH7.2A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execu...
CVE-2018-1990MEDIUM5.3IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration i...
CVE-2018-1790MEDIUM4.3IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forg...
CVE-2018-20837include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.
CVE-2018-5409The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code withou...
CVE-2018-5408The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly va...
CVE-2018-6634A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized user...
CVE-2018-6243NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of vi...
CVE-2018-20503Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
CVE-2018-2008MEDIUM4.3IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 could disclose sensitive information to an authenticated user that coul...
CVE-2018-2001MEDIUM4.3IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which coul...
CVE-2018-19456The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive in...
CVE-2018-14485BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
CVE-2018-14478ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient...
CVE-2018-13994HIGH7.5The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack...
CVE-2018-13993HIGH8.8The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.
CVE-2018-13992HIGH8.2The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of...
CVE-2018-13991MEDIUM5.3The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware image...
CVE-2018-20836HIGH8.1An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_d...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now