2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18979——An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically ...
CVE-2018-18978——An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically ...
CVE-2018-18977——An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reve...
CVE-2018-18976——An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker ...
CVE-2018-18975——An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communicat...
CVE-2018-4073——An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie...
CVE-2018-4072——An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie...
CVE-2018-4071——An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si...
CVE-2018-4070——An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si...
CVE-2018-4067——An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra W...
CVE-2018-4066——An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLin...
CVE-2018-4065——An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wirel...
CVE-2018-4063HIGH8.8An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES4...
CVE-2018-4062——A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activ...
CVE-2018-13990HIGH8.6The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, bec...
CVE-2018-13983——ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/i...
CVE-2018-4069——An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink...
CVE-2018-4068——An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES...
CVE-2018-4061——An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless A...
CVE-2018-17202——Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to p...
CVE-2018-17201——Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be ...
CVE-2018-20824——The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScri...
CVE-2018-20580——The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co...
CVE-2018-15462HIGH7.5A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco F...
CVE-2018-15388HIGH8.6A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thre...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now