2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2018-18326HIGH7.5DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expect...
CVE-2018-18325HIGH7.5DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue ex...
CVE-2018-15812HIGH7.5DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect...
CVE-2018-15811HIGH7.5DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
CVE-2018-6156HIGH8.8Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to pot...
CVE-2018-20847HIGH8.8An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in ...
CVE-2018-1858HIGH8.8IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2018-20843HIGH7.5In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XM...
CVE-2018-16117HIGH8.8A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote au...
CVE-2018-1845HIGH7.1IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack whe...
CVE-2018-20470HIGH7.5An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerab...
CVE-2018-3702HIGH7.8Improper permissions in the installer for the ITE Tech* Consumer Infrared Driver for Windows 10 versions before 5.4.3.0 ...
CVE-2018-10702HIGH8.8An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script...
CVE-2018-10697HIGH8.8An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administ...
CVE-2018-10694HIGH8.1An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not ...
CVE-2018-10690HIGH8.1An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insec...
CVE-2018-13382HIGH7.5An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti...
CVE-2018-13381HIGH7.5A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions a...
CVE-2018-5406HIGH8.8The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-O...
CVE-2018-9193HIGH7.8A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6....
CVE-2018-4048HIGH7.8An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in ...
CVE-2018-7857HIGH7.5A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, a...
CVE-2018-7856HIGH7.5A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, a...
CVE-2018-7855HIGH7.5A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, an...
CVE-2018-7854HIGH7.5A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, an...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now