2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18996 | — | — | 2.5% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, wh... |
| CVE-2018-18992 | — | — | 2.0% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an ... |
| CVE-2018-18990 | — | — | 39.5% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation.... |
| CVE-2018-18986 | — | — | 2.7% | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may caus... |
| CVE-2018-11803 | HIGH | 7.5 | 57.8% | Feb 5, 2019 | Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an unin... |
| CVE-2018-20753 | CRITICAL | 9.8 | 29.3% | Feb 5, 2019 | Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers ... |
| CVE-2018-15659 | — | — | 1.4% | Feb 5, 2019 | An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications.... |
| CVE-2018-15658 | — | — | 1.8% | Feb 5, 2019 | An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.... |
| CVE-2018-15657 | — | — | 1.6% | Feb 5, 2019 | An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter. |
| CVE-2018-15656 | — | — | 1.6% | Feb 5, 2019 | An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a ... |
| CVE-2018-15655 | — | — | 1.4% | Feb 5, 2019 | An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible. |
| CVE-2018-15778 | HIGH | 8.8 | 0.4% | Feb 4, 2019 | Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-li... |
| CVE-2018-20752 | — | — | 3.4% | Feb 4, 2019 | An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV inj... |
| CVE-2018-1970 | HIGH | 7.1 | 1.9% | Feb 4, 2019 | IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML da... |
| CVE-2018-1962 | MEDIUM | 4 | 0.4% | Feb 4, 2019 | IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is press... |
| CVE-2018-1801 | MEDIUM | 5.3 | 2.5% | Feb 4, 2019 | IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.... |
| CVE-2018-1675 | MEDIUM | 6.8 | 1.6% | Feb 4, 2019 | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memor... |
| CVE-2018-1000999 | — | — | — | Feb 4, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: [CVE-2018-20323]. Reason: This candidate is a duplicate o... |
| CVE-2018-1000998 | — | — | 0.9% | Feb 4, 2019 | FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited i... |
| CVE-2018-20751 | — | — | 1.6% | Feb 4, 2019 | An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().Ad... |
| CVE-2018-11760 | — | — | 0.6% | Feb 4, 2019 | When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the us... |
| CVE-2018-19004 | — | — | 3.7% | Feb 1, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, w... |
| CVE-2018-16493 | — | — | 1.8% | Feb 1, 2019 | A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to ... |
| CVE-2018-16492 | — | — | 3.0% | Feb 1, 2019 | A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitra... |
| CVE-2018-16491 | — | — | 1.7% | Feb 1, 2019 | A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now