2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-17923SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to...
CVE-2018-15751SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute ...
CVE-2018-15750Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remo...
CVE-2018-13342The server API in the Anda app relies on hardcoded credentials.
CVE-2018-9281An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the...
CVE-2018-9280An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. Th...
CVE-2018-9279An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page disp...
CVE-2018-18636XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.
CVE-2018-18635www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.0...
CVE-2018-18548ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi...
CVE-2018-18547Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the ...
CVE-2018-18517Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x befor...
CVE-2018-18476mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected datab...
CVE-2018-18013* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated i...
CVE-2018-14812An uncontrolled search path element (DLL Hijacking) vulnerability has been identified in Fuji Electric Energy Savings Es...
CVE-2018-12650Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe...
CVE-2018-11792In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential securi...
CVE-2018-11785Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to injec...
CVE-2018-7432Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light...
CVE-2018-7431Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13...
CVE-2018-7429Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6....
CVE-2018-7427Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6....
CVE-2018-18475Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
CVE-2018-18467An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing o...
CVE-2018-18437In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc paramete...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now