2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18979An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically ...
CVE-2018-18978An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically ...
CVE-2018-18977An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reve...
CVE-2018-18976An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker ...
CVE-2018-18975An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communicat...
CVE-2018-4073An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie...
CVE-2018-4072An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie...
CVE-2018-4071An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si...
CVE-2018-4070An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si...
CVE-2018-4067An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra W...
CVE-2018-4066An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLin...
CVE-2018-4065An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wirel...
CVE-2018-4063HIGH8.8An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES4...
CVE-2018-4062A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activ...
CVE-2018-13990HIGH8.6The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, bec...
CVE-2018-13983ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/i...
CVE-2018-4069An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink...
CVE-2018-4068An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES...
CVE-2018-4061An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless A...
CVE-2018-17202Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to p...
CVE-2018-17201Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be ...
CVE-2018-20824The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScri...
CVE-2018-20580The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co...
CVE-2018-15462HIGH7.5A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco F...
CVE-2018-15388HIGH8.6A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thre...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now