2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20438Technicolor TC7110.AR STD3.38.03 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205...
CVE-2018-20437HIGH7.5An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An a...
CVE-2018-20436The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests...
CVE-2018-20249In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing in...
CVE-2018-20248In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing in...
CVE-2018-20247HIGH7.8In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a ...
CVE-2018-19248The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA d...
CVE-2018-19232The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA d...
CVE-2018-18960An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. They use SNMP to...
CVE-2018-18959An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Prin...
CVE-2018-18698An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store clearte...
CVE-2018-7837An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Mo...
CVE-2018-7836An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 s...
CVE-2018-7835An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in IIoT Monitor 3...
CVE-2018-7832An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause th...
CVE-2018-7802A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web int...
CVE-2018-7801HIGH8.8A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximu...
CVE-2018-7800A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacke...
CVE-2018-7796A Buffer Error vulnerability exists in PowerSuite 2, all released versions (VW3A8104 & Patches), which could cause an ov...
CVE-2018-7793A Credential Management vulnerability exists in FoxView HMI SCADA (All Foxboro DCS, Foxboro Evo, and IA Series versions ...
CVE-2018-8920HIGH7.2Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266...
CVE-2018-8919HIGH8.3Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-1...
CVE-2018-8917MEDIUM6.5Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows rem...
CVE-2018-8918MEDIUM6.5Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote at...
CVE-2018-17197A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.1...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now