2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17923 | — | — | 0.3% | Oct 24, 2018 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to... |
| CVE-2018-15751 | — | — | 5.2% | Oct 24, 2018 | SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute ... |
| CVE-2018-15750 | — | — | 4.2% | Oct 24, 2018 | Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remo... |
| CVE-2018-13342 | — | — | 1.1% | Oct 24, 2018 | The server API in the Anda app relies on hardcoded credentials. |
| CVE-2018-9281 | — | — | 0.4% | Oct 24, 2018 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the... |
| CVE-2018-9280 | — | — | 1.0% | Oct 24, 2018 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. Th... |
| CVE-2018-9279 | — | — | 1.0% | Oct 24, 2018 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page disp... |
| CVE-2018-18636 | — | — | 1.3% | Oct 24, 2018 | XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter. |
| CVE-2018-18635 | — | — | 0.9% | Oct 24, 2018 | www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.0... |
| CVE-2018-18548 | — | — | 3.6% | Oct 24, 2018 | ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi... |
| CVE-2018-18547 | — | — | 1.1% | Oct 24, 2018 | Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the ... |
| CVE-2018-18517 | — | — | 0.8% | Oct 24, 2018 | Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x befor... |
| CVE-2018-18476 | — | — | 1.8% | Oct 24, 2018 | mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected datab... |
| CVE-2018-18013 | — | — | 2.9% | Oct 24, 2018 | * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated i... |
| CVE-2018-14812 | — | — | 1.1% | Oct 24, 2018 | An uncontrolled search path element (DLL Hijacking) vulnerability has been identified in Fuji Electric Energy Savings Es... |
| CVE-2018-12650 | — | — | 2.6% | Oct 24, 2018 | Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe... |
| CVE-2018-11792 | — | — | 2.5% | Oct 24, 2018 | In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential securi... |
| CVE-2018-11785 | — | — | 1.2% | Oct 24, 2018 | Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to injec... |
| CVE-2018-7432 | — | — | 2.3% | Oct 23, 2018 | Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light... |
| CVE-2018-7431 | — | — | 2.3% | Oct 23, 2018 | Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13... |
| CVE-2018-7429 | — | — | 1.7% | Oct 23, 2018 | Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.... |
| CVE-2018-7427 | — | — | 1.0% | Oct 23, 2018 | Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.... |
| CVE-2018-18475 | — | — | 22.1% | Oct 23, 2018 | Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. |
| CVE-2018-18467 | — | — | 1.1% | Oct 23, 2018 | An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing o... |
| CVE-2018-18437 | — | — | 2.3% | Oct 23, 2018 | In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc paramete... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now