2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-5481 | — | — | 0.6% | Jan 7, 2019 | OnCommand Unified Manager for 7-Mode (core package) prior to 5.2.4 uses cookies that lack the secure attribute in certai... |
| CVE-2018-5410 | HIGH | 7.8 | 1.6% | Jan 7, 2019 | Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys dri... |
| CVE-2018-20673 | — | — | 1.6% | Jan 4, 2019 | The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integ... |
| CVE-2018-20671 | — | — | 2.0% | Jan 4, 2019 | load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that ... |
| CVE-2018-1951 | MEDIUM | 5.4 | 1.0% | Jan 4, 2019 | IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2018-1888 | MEDIUM | 5.3 | 1.2% | Jan 4, 2019 | An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitra... |
| CVE-2018-1859 | MEDIUM | 4.3 | 1.0% | Jan 4, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to esca... |
| CVE-2018-1657 | MEDIUM | 5.4 | 1.0% | Jan 4, 2019 | IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2018-8827 | — | — | 1.2% | Jan 3, 2019 | The admin web interface on Technicolor MediaAccess TG789vac v2 HP devices with firmware v16.3.7190-2761005-2016100408435... |
| CVE-2018-4012 | CRITICAL | 9 | 2.5% | Jan 3, 2019 | An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. ... |
| CVE-2018-3986 | MEDIUM | 5.5 | 0.4% | Jan 3, 2019 | An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android m... |
| CVE-2018-19249 | — | — | 1.4% | Jan 3, 2019 | The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens ... |
| CVE-2018-18997 | — | — | 0.9% | Jan 3, 2019 | Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker usi... |
| CVE-2018-18995 | — | — | 2.6% | Jan 3, 2019 | Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configu... |
| CVE-2018-15780 | MEDIUM | 4.3 | 1.2% | Jan 3, 2019 | RSA Archer versions prior to 6.5.0.1 contain an improper access control vulnerability. A remote malicious user could pot... |
| CVE-2018-19601 | — | — | 1.4% | Jan 3, 2019 | Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload. |
| CVE-2018-19600 | — | — | 0.7% | Jan 3, 2019 | Rhymix CMS 1.9.8.1 allows XSS via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload. |
| CVE-2018-18244 | — | — | 0.8% | Jan 3, 2019 | Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote... |
| CVE-2018-18005 | — | — | 0.8% | Jan 3, 2019 | Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows re... |
| CVE-2018-18004 | — | — | 0.9% | Jan 3, 2019 | Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X0... |
| CVE-2018-20664 | — | — | 8.1% | Jan 3, 2019 | Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. |
| CVE-2018-20663 | — | — | 0.7% | Jan 3, 2019 | The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "... |
| CVE-2018-20512 | — | — | 1.8% | Jan 3, 2019 | EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and ti... |
| CVE-2018-19998 | — | — | 2.2% | Jan 3, 2019 | SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbi... |
| CVE-2018-19995 | — | — | 1.1% | Jan 3, 2019 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrar... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now