2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20684 | — | — | 2.5% | Jan 10, 2019 | In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the s... |
| CVE-2018-3703 | — | — | 0.3% | Jan 10, 2019 | Improper directory permissions in the installer for the Intel(R) SSD Data Center Tool for Windows before v3.0.17 may all... |
| CVE-2018-18098 | — | — | 0.3% | Jan 10, 2019 | Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may ... |
| CVE-2018-12177 | — | — | 0.3% | Jan 10, 2019 | Improper directory permissions in the ZeroConfig service in Intel(R) PROSet/Wireless WiFi Software before version 20.90.... |
| CVE-2018-12167 | — | — | 0.3% | Jan 10, 2019 | Firmware update routine in bootloader for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a privileg... |
| CVE-2018-12166 | — | — | 0.3% | Jan 10, 2019 | Insufficient write protection in firmware for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a priv... |
| CVE-2018-16803 | — | — | 2.2% | Jan 10, 2019 | In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code. |
| CVE-2018-20683 | — | — | 2.0% | Jan 10, 2019 | commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows... |
| CVE-2018-20682 | — | — | 0.6% | Jan 9, 2019 | Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the ... |
| CVE-2018-20681 | — | — | 0.6% | Jan 9, 2019 | mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content ... |
| CVE-2018-16205 | — | — | 0.7% | Jan 9, 2019 | Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or... |
| CVE-2018-16203 | — | — | 1.7% | Jan 9, 2019 | PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative pri... |
| CVE-2018-16201 | — | — | 0.6% | Jan 9, 2019 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded crede... |
| CVE-2018-16200 | — | — | 0.7% | Jan 9, 2019 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on... |
| CVE-2018-16199 | — | — | 0.8% | Jan 9, 2019 | Cross-site scripting vulnerability in Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1... |
| CVE-2018-16198 | — | — | 0.5% | Jan 9, 2019 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker... |
| CVE-2018-16197 | — | — | 0.5% | Jan 9, 2019 | Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on... |
| CVE-2018-16196 | — | — | 3.3% | Jan 9, 2019 | Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM C... |
| CVE-2018-16195 | — | — | 0.7% | Jan 9, 2019 | Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and ea... |
| CVE-2018-16194 | — | — | 1.4% | Jan 9, 2019 | Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and ea... |
| CVE-2018-16193 | — | — | 0.5% | Jan 9, 2019 | Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, A... |
| CVE-2018-16192 | — | — | 0.5% | Jan 9, 2019 | Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and ea... |
| CVE-2018-16191 | — | — | 1.3% | Jan 9, 2019 | Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CU... |
| CVE-2018-16188 | — | — | 1.9% | Jan 9, 2019 | SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2... |
| CVE-2018-16187 | — | — | 0.5% | Jan 9, 2019 | The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with R... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now