2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18996LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, wh...
CVE-2018-18992LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an ...
CVE-2018-18990LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation....
CVE-2018-18986LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may caus...
CVE-2018-11803HIGH7.5Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an unin...
CVE-2018-20753CRITICAL9.8Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers ...
CVE-2018-15659An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications....
CVE-2018-15658An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master....
CVE-2018-15657An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
CVE-2018-15656An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a ...
CVE-2018-15655An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible.
CVE-2018-15778HIGH8.8Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-li...
CVE-2018-20752An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV inj...
CVE-2018-1970HIGH7.1IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML da...
CVE-2018-1962MEDIUM4IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is press...
CVE-2018-1801MEDIUM5.3IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0....
CVE-2018-1675MEDIUM6.8IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memor...
CVE-2018-1000999Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: [CVE-2018-20323]. Reason: This candidate is a duplicate o...
CVE-2018-1000998FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited i...
CVE-2018-20751An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().Ad...
CVE-2018-11760When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the us...
CVE-2018-19004LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, w...
CVE-2018-16493A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to ...
CVE-2018-16492A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitra...
CVE-2018-16491A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now