2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-20148In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted meta...
CVE-2018-20147In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deletin...
CVE-2018-19007In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration pa...
CVE-2018-19413A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive i...
CVE-2018-19003GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C...
CVE-2018-18006Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any exte...
CVE-2018-3705Improper directory permissions in the installer for the Intel(R) System Defense Utility (all versions) may allow authent...
CVE-2018-3704Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated u...
CVE-2018-18097Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potent...
CVE-2018-18096Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to pot...
CVE-2018-18093Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged use...
CVE-2018-12206Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenti...
CVE-2018-5411Pixar's Tractor software, versions 2.2 and earlier, contain a stored cross-site scripting vulnerability in the field tha...
CVE-2018-20145Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the def...
CVE-2018-19439XSS exists in the Administration Console in Oracle Secure Global Desktop 4.4 20080807152602 (but was fixed in later vers...
CVE-2018-19118Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer...
CVE-2018-19039Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor...
CVE-2018-18923AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and ...
CVE-2018-18922add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POS...
CVE-2018-12076A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to a...
CVE-2018-20137XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demo...
CVE-2018-20136XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by...
CVE-2018-16555A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1),...
CVE-2018-13815A vulnerability has been identified in SIMATIC S7-1200 (All versions), SIMATIC S7-1500 (All Versions < V2.6). An attacke...
CVE-2018-13814A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Out...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now