2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15818 | — | — | 2.0% | Mar 21, 2019 | An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web... |
| CVE-2018-15532 | — | — | 0.7% | Mar 21, 2019 | SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed... |
| CVE-2018-15508 | — | — | 1.8% | Mar 21, 2019 | Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service v... |
| CVE-2018-15498 | — | — | 1.2% | Mar 21, 2019 | YSoft SafeQ Server 6 allows a replay attack. |
| CVE-2018-14745 | — | — | 1.9% | Mar 21, 2019 | Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 al... |
| CVE-2018-14724 | — | — | 0.7% | Mar 21, 2019 | In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ... |
| CVE-2018-14575 | — | — | 2.4% | Mar 21, 2019 | Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CS... |
| CVE-2018-14486 | — | — | 1.1% | Mar 21, 2019 | DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML. |
| CVE-2018-13104 | — | — | 0.8% | Mar 21, 2019 | OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID) |
| CVE-2018-13103 | — | — | 0.9% | Mar 21, 2019 | OX App Suite 7.8.4 and earlier allows SSRF. |
| CVE-2018-12638 | — | — | 1.1% | Mar 21, 2019 | An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device n... |
| CVE-2018-12572 | — | — | 0.3% | Mar 21, 2019 | Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain... |
| CVE-2018-12023 | — | — | 8.9% | Mar 21, 2019 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enab... |
| CVE-2018-12022 | HIGH | 7.5 | 7.3% | Mar 21, 2019 | An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enab... |
| CVE-2018-11789 | — | — | 6.9% | Mar 21, 2019 | When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any fil... |
| CVE-2018-11767 | — | — | 3.7% | Mar 21, 2019 | In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrec... |
| CVE-2018-11747 | — | — | 0.7% | Mar 21, 2019 | Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4... |
| CVE-2018-10093 | — | — | 68.7% | Mar 21, 2019 | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution. |
| CVE-2018-10091 | — | — | 0.8% | Mar 21, 2019 | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS. |
| CVE-2018-0265 | — | — | — | Mar 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-0246 | — | — | — | Mar 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-0236 | — | — | — | Mar 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-0153 | — | — | — | Mar 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-0191 | — | — | — | Mar 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-0143 | — | — | — | Mar 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now