2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1729MEDIUM5.3IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further ...
CVE-2018-20200CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by ...
CVE-2018-17289An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 a...
CVE-2018-17288Kofax Front Office Server version 4.1.1.11.0.5212 (both Thin Client and Administration Console) suffers from multiple au...
CVE-2018-17287In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in t...
CVE-2018-16878MEDIUM5.5A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of un...
CVE-2018-16877HIGH7.8A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0...
CVE-2018-17168PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration pag...
CVE-2018-0382MEDIUM5.3A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN ...
CVE-2018-0248MEDIUM6.8A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could al...
CVE-2018-20028Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
CVE-2018-18094Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to p...
CVE-2018-7340HIGH7.5Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs...
CVE-2018-4007HIGH7.1An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig fun...
CVE-2018-4006HIGH7.8An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig func...
CVE-2018-4005HIGH7.8An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRouting...
CVE-2018-4004MEDIUM5.5An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectServic...
CVE-2018-13378An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext...
CVE-2018-10959Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by ...
CVE-2018-16561HIGH7.5A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly valida...
CVE-2018-16559A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All v...
CVE-2018-16558A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All v...
CVE-2018-13810A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web ...
CVE-2018-13809A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated web server of the ...
CVE-2018-13808A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). An attacker with network access t...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now