2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18326 | HIGH | 7.5 | 53.6% | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expect... |
| CVE-2018-18325 | HIGH | 7.5 | 74.0% | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue ex... |
| CVE-2018-15812 | HIGH | 7.5 | 46.5% | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect... |
| CVE-2018-15811 | HIGH | 7.5 | 74.0% | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. |
| CVE-2018-6156 | HIGH | 8.8 | 0.9% | Jun 27, 2019 | Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to pot... |
| CVE-2018-20847 | HIGH | 8.8 | 2.2% | Jun 26, 2019 | An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in ... |
| CVE-2018-1858 | HIGH | 8.8 | 0.9% | Jun 25, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to exe... |
| CVE-2018-20843 | HIGH | 7.5 | 7.1% | Jun 24, 2019 | In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XM... |
| CVE-2018-16117 | HIGH | 8.8 | 44.3% | Jun 20, 2019 | A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote au... |
| CVE-2018-1845 | HIGH | 7.1 | 2.0% | Jun 17, 2019 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack whe... |
| CVE-2018-20470 | HIGH | 7.5 | 46.0% | Jun 17, 2019 | An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerab... |
| CVE-2018-3702 | HIGH | 7.8 | 0.3% | Jun 13, 2019 | Improper permissions in the installer for the ITE Tech* Consumer Infrared Driver for Windows 10 versions before 5.4.3.0 ... |
| CVE-2018-10702 | HIGH | 8.8 | 5.3% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script... |
| CVE-2018-10697 | HIGH | 8.8 | 3.7% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administ... |
| CVE-2018-10694 | HIGH | 8.1 | 0.8% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not ... |
| CVE-2018-10690 | HIGH | 8.1 | 1.5% | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insec... |
| CVE-2018-13382 | HIGH | 7.5 | 81.7% | Jun 4, 2019 | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti... |
| CVE-2018-13381 | HIGH | 7.5 | 1.8% | Jun 4, 2019 | A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions a... |
| CVE-2018-5406 | HIGH | 8.8 | 12.2% | Jun 3, 2019 | The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-O... |
| CVE-2018-9193 | HIGH | 7.8 | 0.4% | May 30, 2019 | A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.... |
| CVE-2018-4048 | HIGH | 7.8 | 0.6% | May 30, 2019 | An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in ... |
| CVE-2018-7857 | HIGH | 7.5 | 1.6% | May 22, 2019 | A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, a... |
| CVE-2018-7856 | HIGH | 7.5 | 1.6% | May 22, 2019 | A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, a... |
| CVE-2018-7855 | HIGH | 7.5 | 2.6% | May 22, 2019 | A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, an... |
| CVE-2018-7854 | HIGH | 7.5 | 2.3% | May 22, 2019 | A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, an... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now