2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-16186——RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH...
CVE-2018-16185——RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH...
CVE-2018-16184——RICOH Interactive Whiteboard D2200 V1.6 to V2.2, D5500 V1.6 to V2.2, D5510 V1.6 to V2.2, and the display versions with R...
CVE-2018-16183——An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windo...
CVE-2018-16182——Untrusted search path vulnerability in the installer of MARKET SPEED Ver.16.4 and earlier allows an attacker to gain pri...
CVE-2018-16181——HTTP header injection vulnerability in i-FILTER Ver.9.50R05 and earlier may allow remote attackers to inject arbitrary H...
CVE-2018-16180——Cross-site scripting vulnerability in i-FILTER Ver.9.50R05 and earlier allows remote attackers to inject arbitrary web s...
CVE-2018-16179——The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-th...
CVE-2018-16178——Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only fo...
CVE-2018-16176——Untrusted search path vulnerability in Installer of Mapping Tool 2.0.1.6 and 2.0.1.7 allows remote attackers to gain pri...
CVE-2018-16175——SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execut...
CVE-2018-16174——Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary ...
CVE-2018-16173——Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web ...
CVE-2018-16172——Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Re...
CVE-2018-16171——Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code f...
CVE-2018-16170——Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attack...
CVE-2018-16169——Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the s...
CVE-2018-16168——LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
CVE-2018-16167——LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2018-16166——LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vecto...
CVE-2018-16165——Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web scri...
CVE-2018-16164——Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers...
CVE-2018-1000425——An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in Sona...
CVE-2018-1000424——An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in Artifac...
CVE-2018-1000423——An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now