2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17968 | — | — | 1.2% | Oct 23, 2018 | A gambling smart contract implementation for RuletkaIo, an Ethereum gambling game, generates a random value that is pred... |
| CVE-2018-17877 | — | — | 1.6% | Oct 23, 2018 | A lottery smart contract implementation for Greedy 599, an Ethereum gambling game, generates a random value that is pred... |
| CVE-2018-17873 | — | — | 1.9% | Oct 23, 2018 | An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 ... |
| CVE-2018-17448 | — | — | 2.2% | Oct 23, 2018 | An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.... |
| CVE-2018-17447 | — | — | 1.9% | Oct 23, 2018 | An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before... |
| CVE-2018-17446 | — | — | 2.0% | Oct 23, 2018 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 1... |
| CVE-2018-17445 | — | — | 11.1% | Oct 23, 2018 | A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x befo... |
| CVE-2018-17444 | — | — | 3.6% | Oct 23, 2018 | A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x be... |
| CVE-2018-16235 | — | — | 0.9% | Oct 23, 2018 | Telligent Community 6.x, 7.x, 8.x, 9.x before 9.2.10.11796, 10.1.x before 10.1.10.11792, and 10.2.x before 10.2.3.4725 h... |
| CVE-2018-16226 | — | — | 1.1% | Oct 23, 2018 | A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could a... |
| CVE-2018-15497 | — | — | 4.9% | Oct 23, 2018 | The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.... |
| CVE-2018-12901 | — | — | 1.1% | Oct 23, 2018 | A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an... |
| CVE-2018-18628 | — | — | 5.5% | Oct 23, 2018 | An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStrea... |
| CVE-2018-14828 | — | — | 0.4% | Oct 23, 2018 | Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to... |
| CVE-2018-14820 | — | — | 2.2% | Oct 23, 2018 | Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path ... |
| CVE-2018-14806 | — | — | 4.8% | Oct 23, 2018 | Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrar... |
| CVE-2018-18626 | — | — | 0.9% | Oct 23, 2018 | An issue was discovered in PHPYun V4.6. There is a vulnerability that can delete any file or directory via the "admin/in... |
| CVE-2018-18622 | — | — | 0.7% | Oct 23, 2018 | An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username para... |
| CVE-2018-18608 | — | — | 2.6% | Oct 23, 2018 | DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is u... |
| CVE-2018-8569 | — | — | 13.3% | Oct 23, 2018 | A remote code execution vulnerability exists in the Yammer desktop application due to the loading of arbitrary content, ... |
| CVE-2018-18607 | — | — | 2.2% | Oct 23, 2018 | An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as ... |
| CVE-2018-18606 | — | — | 2.2% | Oct 23, 2018 | An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd... |
| CVE-2018-18605 | — | — | 2.3% | Oct 23, 2018 | A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File D... |
| CVE-2018-18603 | — | — | 0.9% | Oct 23, 2018 | 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.s... |
| CVE-2018-18599 | — | — | 1.5% | Oct 23, 2018 | Stegdetect through 2018-05-26 has an out-of-bounds write in f5_compress in the f5.c file. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now