2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20487An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC ...
CVE-2018-19202A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via...
CVE-2018-17305UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even ad...
CVE-2018-19300On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) bef...
CVE-2018-14683PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI.
CVE-2018-19453HIGH8.8Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type.
CVE-2018-1994MEDIUM6.3IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-c...
CVE-2018-1903MEDIUM6.7IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system ...
CVE-2018-20321An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount th...
CVE-2018-1356A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execut...
CVE-2018-18365Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to dis...
CVE-2018-7118A local access restriction bypass vulnerability was identified in HPE Service Pack for ProLiant (SPP) Bundled Software e...
CVE-2018-7117A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out ...
CVE-2018-16530CRITICAL9.8A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and p...
CVE-2018-18507Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2018-20698The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page wh...
CVE-2018-19586Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered du...
CVE-2018-14894CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file...
CVE-2018-19589Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM pr...
CVE-2018-13366An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial num...
CVE-2018-15640HIGH8.8Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers t...
CVE-2018-15635MEDIUM5.9Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and e...
CVE-2018-15631MEDIUM6.5Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allo...
CVE-2018-20341WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an ...
CVE-2018-2000MEDIUM4.3IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now