2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18940servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary par...
CVE-2018-15517The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an...
CVE-2018-15516The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT comma...
CVE-2018-15515The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dl...
CVE-2018-17926The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker ...
CVE-2018-11790When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating s...
CVE-2018-3956HIGH7.1An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Softwa...
CVE-2018-17199In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the sessi...
CVE-2018-17189MEDIUM5.3In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h...
CVE-2018-20750CRITICAL9.8LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-201...
CVE-2018-20749CRITICAL9.8LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018...
CVE-2018-20748CRITICAL9.8LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for ...
CVE-2018-19027Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when...
CVE-2018-19858PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an at...
CVE-2018-19782Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject ...
CVE-2018-19440MEDIUM5.3ARM Trusted Firmware-A allows information disclosure.
CVE-2018-18895Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3004. Reason: This candidate is a duplicate of...
CVE-2018-17431CRITICAL9.8Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication...
CVE-2018-15136TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filt...
CVE-2018-12611OX App Suite 7.8.4 and earlier allows Directory Traversal.
CVE-2018-12610OX App Suite 7.8.4 and earlier allows Information Exposure.
CVE-2018-12609OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
CVE-2018-1976MEDIUM4.9IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow ...
CVE-2018-18985Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8....
CVE-2018-1733MEDIUM5.3IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane impl...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now