2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1729 | MEDIUM | 5.3 | 1.8% | Apr 19, 2019 | IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further ... |
| CVE-2018-20200 | — | — | 2.5% | Apr 18, 2019 | CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by ... |
| CVE-2018-17289 | — | — | 1.5% | Apr 18, 2019 | An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 a... |
| CVE-2018-17288 | — | — | 0.6% | Apr 18, 2019 | Kofax Front Office Server version 4.1.1.11.0.5212 (both Thin Client and Administration Console) suffers from multiple au... |
| CVE-2018-17287 | — | — | 0.4% | Apr 18, 2019 | In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in t... |
| CVE-2018-16878 | MEDIUM | 5.5 | 0.4% | Apr 18, 2019 | A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of un... |
| CVE-2018-16877 | HIGH | 7.8 | 0.4% | Apr 18, 2019 | A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0... |
| CVE-2018-17168 | — | — | 0.5% | Apr 18, 2019 | PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration pag... |
| CVE-2018-0382 | MEDIUM | 5.3 | 2.0% | Apr 17, 2019 | A vulnerability in the session identification management functionality of the web-based interface of Cisco Wireless LAN ... |
| CVE-2018-0248 | MEDIUM | 6.8 | 2.0% | Apr 17, 2019 | A vulnerability in the administrative GUI configuration feature of Cisco Wireless LAN Controller (WLC) Software could al... |
| CVE-2018-20028 | — | — | 0.9% | Apr 17, 2019 | Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control. |
| CVE-2018-18094 | — | — | 0.3% | Apr 17, 2019 | Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to p... |
| CVE-2018-7340 | HIGH | 7.5 | 1.0% | Apr 17, 2019 | Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs... |
| CVE-2018-4007 | HIGH | 7.1 | 0.4% | Apr 17, 2019 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig fun... |
| CVE-2018-4006 | HIGH | 7.8 | 0.7% | Apr 17, 2019 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the writeConfig func... |
| CVE-2018-4005 | HIGH | 7.8 | 0.7% | Apr 17, 2019 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the configureRouting... |
| CVE-2018-4004 | MEDIUM | 5.5 | 0.4% | Apr 17, 2019 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the disconnectServic... |
| CVE-2018-13378 | — | — | 1.3% | Apr 17, 2019 | An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext... |
| CVE-2018-10959 | — | — | 1.6% | Apr 17, 2019 | Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by ... |
| CVE-2018-16561 | HIGH | 7.5 | 1.4% | Apr 17, 2019 | A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly valida... |
| CVE-2018-16559 | — | — | 2.0% | Apr 17, 2019 | A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All v... |
| CVE-2018-16558 | — | — | 2.0% | Apr 17, 2019 | A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All v... |
| CVE-2018-13810 | — | — | 0.5% | Apr 17, 2019 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web ... |
| CVE-2018-13809 | — | — | 0.8% | Apr 17, 2019 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated web server of the ... |
| CVE-2018-13808 | — | — | 1.8% | Apr 17, 2019 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). An attacker with network access t... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now