2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-17996LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_...
CVE-2018-17502MEDIUM4The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contac...
CVE-2018-17500LOW2.9Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, c...
CVE-2018-17499LOW2.9Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, c...
CVE-2018-17497HIGH8.4eVisitorPass contains default administrative credentials. An attacker could exploit this vulnerability to gain full acce...
CVE-2018-17496HIGH8.4eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error while in kiosk m...
CVE-2018-17495HIGH8.4eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Virtual...
CVE-2018-17494HIGH8.4eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Virtual...
CVE-2018-17493HIGH8.4eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Fullscr...
CVE-2018-17492HIGH8.4EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full ac...
CVE-2018-17491HIGH8.4EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing ...
CVE-2018-17490HIGH7.7EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attac...
CVE-2018-17489LOW2.9EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social securit...
CVE-2018-17488HIGH8.4Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the pr...
CVE-2018-17487HIGH8.4Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the pr...
CVE-2018-17486LOW2.9Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor...
CVE-2018-17485HIGH8.4Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain fu...
CVE-2018-17484MEDIUM4Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database....
CVE-2018-17483LOW2.9Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in...
CVE-2018-17482MEDIUM4Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in...
CVE-2018-17167PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name...
CVE-2018-16789libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a cra...
CVE-2018-16563A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firm...
CVE-2018-16519COYO 9.0.8, 10.0.11 and 12.0.4 has cross-site scripting (XSS) via URLs used by "iFrame" widgets.
CVE-2018-15906SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now