2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18388 | — | — | 1.5% | Dec 20, 2018 | eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to... |
| CVE-2018-16627 | — | — | 0.8% | Dec 20, 2018 | panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. |
| CVE-2018-14846 | — | — | 1.1% | Dec 20, 2018 | The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php. |
| CVE-2018-12651 | — | — | 0.9% | Dec 20, 2018 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied in... |
| CVE-2018-17247 | — | — | 1.4% | Dec 20, 2018 | Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a ... |
| CVE-2018-17246 | — | — | 82.3% | Dec 20, 2018 | Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with... |
| CVE-2018-17245 | — | — | 1.3% | Dec 20, 2018 | Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are us... |
| CVE-2018-17244 | — | — | 1.5% | Dec 20, 2018 | Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when ... |
| CVE-2018-19005 | — | — | 1.7% | Dec 20, 2018 | Cscape, Version 9.80.75.3 SP3 and prior. An improper input validation vulnerability has been identified that may be expl... |
| CVE-2018-18871 | — | — | 1.7% | Dec 20, 2018 | Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow... |
| CVE-2018-15723 | — | — | 3.7% | Dec 20, 2018 | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP r... |
| CVE-2018-15722 | — | — | 1.6% | Dec 20, 2018 | The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A re... |
| CVE-2018-15721 | — | — | 1.8% | Dec 20, 2018 | The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMP... |
| CVE-2018-15720 | — | — | 1.5% | Dec 20, 2018 | Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users... |
| CVE-2018-1000886 | — | — | 0.8% | Dec 20, 2018 | nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-ove... |
| CVE-2018-1000885 | — | — | 3.2% | Dec 20, 2018 | PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Ele... |
| CVE-2018-1000884 | — | — | 1.3% | Dec 20, 2018 | Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CW... |
| CVE-2018-1000883 | — | — | 1.1% | Dec 20, 2018 | Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie v... |
| CVE-2018-8892 | — | — | 0.4% | Dec 20, 2018 | A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9... |
| CVE-2018-8891 | — | — | 0.5% | Dec 20, 2018 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier ... |
| CVE-2018-8888 | — | — | 0.5% | Dec 20, 2018 | A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.1... |
| CVE-2018-15331 | — | — | 0.9% | Dec 20, 2018 | On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions whe... |
| CVE-2018-15330 | — | — | 1.3% | Dec 20, 2018 | On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to... |
| CVE-2018-15329 | — | — | 1.2% | Dec 20, 2018 | On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administ... |
| CVE-2018-19234 | — | — | 3.3% | Dec 20, 2018 | The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows remote attackers to execute... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now