2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18940 | — | — | 1.4% | Jan 31, 2019 | servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary par... |
| CVE-2018-15517 | — | — | 44.1% | Jan 31, 2019 | The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an... |
| CVE-2018-15516 | — | — | 2.0% | Jan 31, 2019 | The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT comma... |
| CVE-2018-15515 | — | — | 1.7% | Jan 31, 2019 | The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dl... |
| CVE-2018-17926 | — | — | 0.8% | Jan 31, 2019 | The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker ... |
| CVE-2018-11790 | — | — | 1.0% | Jan 31, 2019 | When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating s... |
| CVE-2018-3956 | HIGH | 7.1 | 49.6% | Jan 30, 2019 | An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Softwa... |
| CVE-2018-17199 | — | — | 20.0% | Jan 30, 2019 | In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the sessi... |
| CVE-2018-17189 | MEDIUM | 5.3 | 19.4% | Jan 30, 2019 | In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h... |
| CVE-2018-20750 | CRITICAL | 9.8 | 3.3% | Jan 30, 2019 | LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-201... |
| CVE-2018-20749 | CRITICAL | 9.8 | 3.2% | Jan 30, 2019 | LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018... |
| CVE-2018-20748 | CRITICAL | 9.8 | 3.2% | Jan 30, 2019 | LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for ... |
| CVE-2018-19027 | — | — | 1.4% | Jan 30, 2019 | Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when... |
| CVE-2018-19858 | — | — | 2.6% | Jan 30, 2019 | PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an at... |
| CVE-2018-19782 | — | — | 4.4% | Jan 30, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject ... |
| CVE-2018-19440 | MEDIUM | 5.3 | 1.4% | Jan 30, 2019 | ARM Trusted Firmware-A allows information disclosure. |
| CVE-2018-18895 | — | — | — | Jan 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3004. Reason: This candidate is a duplicate of... |
| CVE-2018-17431 | CRITICAL | 9.8 | 84.3% | Jan 30, 2019 | Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication... |
| CVE-2018-15136 | — | — | 1.0% | Jan 30, 2019 | TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filt... |
| CVE-2018-12611 | — | — | 1.2% | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Directory Traversal. |
| CVE-2018-12610 | — | — | 1.2% | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Information Exposure. |
| CVE-2018-12609 | — | — | 1.0% | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery. |
| CVE-2018-1976 | MEDIUM | 4.9 | 1.7% | Jan 29, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow ... |
| CVE-2018-18985 | — | — | 1.0% | Jan 29, 2019 | Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.... |
| CVE-2018-1733 | MEDIUM | 5.3 | 1.7% | Jan 29, 2019 | IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane impl... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now