2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-25139HIGH8.7FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live vi...
CVE-2018-25138CRITICAL9.8FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal ...
CVE-2018-25137HIGH8.7FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows att...
CVE-2018-25136HIGH8.7FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live ...
CVE-2018-25135CRITICAL9.8Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by...
CVE-2018-25134CRITICAL9.8Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that ...
CVE-2018-25133MEDIUM5.1Synaccess netBooter NP-0801DU 7.4 contains a cross-site request forgery vulnerability that allows attackers to perform a...
CVE-2018-25131HIGH7.2Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a stored cross-site scripting vulnerability in the configura...
CVE-2018-25130MEDIUM6.8Beward Intercom 2.3.1 contains a credentials disclosure vulnerability that allows local attackers to access plain-text a...
CVE-2018-25129HIGH7.5SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attacker...
CVE-2018-25128CRITICAL9.3SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate dat...
CVE-2018-25127MEDIUM5.3SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform a...
CVE-2018-25126CRITICAL9.3Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains ...
CVE-2018-25125HIGH8.7Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that a...
CVE-2018-25124HIGH8.7PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within th...
CVE-2018-25123HIGH7.8Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-rela...
CVE-2018-25122HIGH8.8Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The dow...
CVE-2018-25121MEDIUM5.4Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface....
CVE-2018-25119MEDIUM6.1Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Ins...
CVE-2018-25120CRITICAL9.8D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulner...
CVE-2018-25118CRITICAL10GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability v...
CVE-2018-25117CRITICAL9.3VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a...
CVE-2018-25115CRITICAL9.8Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware...
CVE-2018-25114CRITICAL9.3A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default c...
CVE-2018-25113HIGH8.7An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. T...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now