2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11905 | — | — | 0.9% | Dec 7, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buff... |
| CVE-2018-19932 | — | — | 1.9% | Dec 7, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through... |
| CVE-2018-19927 | — | — | 0.6% | Dec 6, 2018 | Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Setting... |
| CVE-2018-19926 | — | — | 0.7% | Dec 6, 2018 | Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO. |
| CVE-2018-19925 | — | — | 1.1% | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the mem... |
| CVE-2018-19924 | — | — | 0.7% | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified... |
| CVE-2018-19923 | — | — | 0.5% | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php... |
| CVE-2018-19660 | — | — | 30.9% | Dec 6, 2018 | An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A... |
| CVE-2018-19659 | — | — | 4.3% | Dec 6, 2018 | An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A... |
| CVE-2018-16603 | — | — | 1.8% | Dec 6, 2018 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),... |
| CVE-2018-16602 | — | — | 1.8% | Dec 6, 2018 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),... |
| CVE-2018-16601 | — | — | 4.2% | Dec 6, 2018 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),... |
| CVE-2018-16600 | — | — | 1.8% | Dec 6, 2018 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),... |
| CVE-2018-16599 | — | — | 1.8% | Dec 6, 2018 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),... |
| CVE-2018-16598 | — | — | 1.5% | Dec 6, 2018 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP),... |
| CVE-2018-16528 | — | — | 3.3% | Dec 6, 2018 | Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS co... |
| CVE-2018-16527 | — | — | 1.8% | Dec 6, 2018 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne... |
| CVE-2018-16526 | — | — | 4.5% | Dec 6, 2018 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne... |
| CVE-2018-16525 | — | — | 4.5% | Dec 6, 2018 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne... |
| CVE-2018-16524 | — | — | 1.8% | Dec 6, 2018 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne... |
| CVE-2018-16523 | — | — | 2.1% | Dec 6, 2018 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Conne... |
| CVE-2018-16522 | — | — | 2.1% | Dec 6, 2018 | Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt. |
| CVE-2018-19922 | — | — | 0.8% | Dec 6, 2018 | Persistent Cross-Site Scripting (XSS) in the advancedsetup_websiteblocking.html Website Blocking page of the Actiontec C... |
| CVE-2018-19921 | — | — | 1.9% | Dec 6, 2018 | Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller. |
| CVE-2018-19919 | — | — | 0.7% | Dec 6, 2018 | Pixelimity 1.0 has Persistent XSS via the admin/portfolio.php data[title] parameter, as demonstrated by a crafted onload... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now