2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20487 | — | — | 1.9% | Apr 11, 2019 | An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC ... |
| CVE-2018-19202 | — | — | 0.8% | Apr 11, 2019 | A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via... |
| CVE-2018-17305 | — | — | 1.5% | Apr 11, 2019 | UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even ad... |
| CVE-2018-19300 | — | — | 74.3% | Apr 11, 2019 | On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) bef... |
| CVE-2018-14683 | — | — | 0.6% | Apr 10, 2019 | PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI. |
| CVE-2018-19453 | HIGH | 8.8 | 1.4% | Apr 10, 2019 | Kentico CMS before 11.0.45 allows unrestricted upload of a file with a dangerous type. |
| CVE-2018-1994 | MEDIUM | 6.3 | 1.6% | Apr 10, 2019 | IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-c... |
| CVE-2018-1903 | MEDIUM | 6.7 | 0.4% | Apr 10, 2019 | IBM Sterling Connect:Direct for UNIX 4.2.0, 4.3.0, and 6.0.0 could allow a user with restricted sudo access on a system ... |
| CVE-2018-20321 | — | — | 1.8% | Apr 10, 2019 | An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount th... |
| CVE-2018-1356 | — | — | 0.9% | Apr 9, 2019 | A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execut... |
| CVE-2018-18365 | — | — | 1.3% | Apr 9, 2019 | Norton Password Manager may be susceptible to an address spoofing issue. This type of issue may allow an attacker to dis... |
| CVE-2018-7118 | — | — | 0.5% | Apr 9, 2019 | A local access restriction bypass vulnerability was identified in HPE Service Pack for ProLiant (SPP) Bundled Software e... |
| CVE-2018-7117 | — | — | 1.3% | Apr 9, 2019 | A remote Cross-Site Scripting in HPE iLO 5 Web User Interface vulnerability was identified in HPE Integrated Lights-Out ... |
| CVE-2018-16530 | CRITICAL | 9.8 | 3.4% | Apr 9, 2019 | A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and p... |
| CVE-2018-18507 | — | — | — | Apr 9, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-20698 | — | — | 0.8% | Apr 9, 2019 | The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page wh... |
| CVE-2018-19586 | — | — | 5.1% | Apr 9, 2019 | Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered du... |
| CVE-2018-14894 | — | — | 1.9% | Apr 9, 2019 | CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file... |
| CVE-2018-19589 | — | — | 0.7% | Apr 9, 2019 | Incorrect Access Controls of Security Officer (SO) in PKCS11 R2 provider that ships with the Utimaco CryptoServer HSM pr... |
| CVE-2018-13366 | — | — | 0.9% | Apr 9, 2019 | An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial num... |
| CVE-2018-15640 | HIGH | 8.8 | 7.9% | Apr 9, 2019 | Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers t... |
| CVE-2018-15635 | MEDIUM | 5.9 | 1.0% | Apr 9, 2019 | Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and e... |
| CVE-2018-15631 | MEDIUM | 6.5 | 1.4% | Apr 9, 2019 | Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allo... |
| CVE-2018-20341 | — | — | 0.3% | Apr 8, 2019 | WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an ... |
| CVE-2018-2000 | MEDIUM | 4.3 | 0.8% | Apr 8, 2019 | IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now