2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1680 | MEDIUM | 5.9 | 1.5% | Apr 2, 2019 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong password... |
| CVE-2018-1640 | HIGH | 8.8 | 3.7% | Apr 2, 2019 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote authenticated attacker to execute ... |
| CVE-2018-1626 | LOW | 3.1 | 1.2% | Apr 2, 2019 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session variable after a successful au... |
| CVE-2018-1625 | MEDIUM | 4.3 | 1.0% | Apr 2, 2019 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 generates an error message that includes sensitive info... |
| CVE-2018-1623 | MEDIUM | 4 | 0.4% | Apr 2, 2019 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 allows web pages to be stored locally which can be read... |
| CVE-2018-1622 | MEDIUM | 4.3 | 0.5% | Apr 2, 2019 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 is vulnerable to cross-site request forgery which could... |
| CVE-2018-1618 | HIGH | 7.7 | 3.4% | Apr 2, 2019 | IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 could allow a remote attacker to traverse directories o... |
| CVE-2018-3979 | MEDIUM | 6.5 | 1.4% | Apr 1, 2019 | A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display... |
| CVE-2018-19113 | — | — | 0.8% | Apr 1, 2019 | The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)... |
| CVE-2018-17990 | — | — | 4.5% | Apr 1, 2019 | An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp ... |
| CVE-2018-17989 | — | — | 0.8% | Apr 1, 2019 | A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authent... |
| CVE-2018-17565 | — | — | 1.9% | Apr 1, 2019 | Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows att... |
| CVE-2018-17564 | — | — | 1.6% | Apr 1, 2019 | A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete c... |
| CVE-2018-17563 | — | — | 0.7% | Apr 1, 2019 | A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers t... |
| CVE-2018-4050 | HIGH | 7.8 | 0.4% | Apr 1, 2019 | An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, vers... |
| CVE-2018-5757 | — | — | 7.8% | Apr 1, 2019 | An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functi... |
| CVE-2018-8913 | HIGH | 7.1 | 1.1% | Apr 1, 2019 | Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phi... |
| CVE-2018-13299 | MEDIUM | 4.3 | 1.4% | Apr 1, 2019 | Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authen... |
| CVE-2018-13298 | MEDIUM | 4.2 | 0.9% | Apr 1, 2019 | Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man... |
| CVE-2018-13297 | MEDIUM | 5.3 | 1.5% | Apr 1, 2019 | Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attack... |
| CVE-2018-13296 | HIGH | 7.5 | 1.8% | Apr 1, 2019 | Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allow... |
| CVE-2018-13295 | MEDIUM | 4.3 | 1.3% | Apr 1, 2019 | Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 a... |
| CVE-2018-13294 | MEDIUM | 4.3 | 1.3% | Apr 1, 2019 | Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows rem... |
| CVE-2018-13293 | MEDIUM | 5.9 | 0.8% | Apr 1, 2019 | Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.... |
| CVE-2018-13292 | MEDIUM | 4.3 | 1.3% | Apr 1, 2019 | Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allo... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now