2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13814 | — | — | 1.7% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Out... |
| CVE-2018-13813 | — | — | 1.7% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Co... |
| CVE-2018-13812 | — | — | 3.6% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Co... |
| CVE-2018-13811 | — | — | 0.2% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insuffic... |
| CVE-2018-13804 | — | — | 2.7% | Dec 13, 2018 | A vulnerability has been identified in SIMATIC IT LMS (All versions), SIMATIC IT Production Suite (Versions V7.1 < V7.1 ... |
| CVE-2018-8033 | — | — | 25.7% | Dec 13, 2018 | In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles re... |
| CVE-2018-7691 | MEDIUM | 6.5 | 7.2% | Dec 13, 2018 | A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.... |
| CVE-2018-7690 | MEDIUM | 6.5 | 7.4% | Dec 13, 2018 | A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.... |
| CVE-2018-20129 | — | — | 8.2% | Dec 13, 2018 | An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to up... |
| CVE-2018-20128 | — | — | 1.5% | Dec 13, 2018 | An issue was discovered in UsualToolCMS v8.0. cmsadmin\a_sqlback.php allows remote attackers to delete arbitrary files v... |
| CVE-2018-20127 | HIGH | 7.5 | 1.4% | Dec 13, 2018 | An issue was discovered in zzzphp cms 1.5.8. del_file in /admin/save.php allows remote attackers to delete arbitrary fil... |
| CVE-2018-6706 | HIGH | 7.5 | 0.6% | Dec 12, 2018 | Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivi... |
| CVE-2018-6705 | HIGH | 7.8 | 0.4% | Dec 12, 2018 | Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local use... |
| CVE-2018-6704 | HIGH | 7.8 | 0.4% | Dec 12, 2018 | Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local use... |
| CVE-2018-15719 | — | — | 1.1% | Dec 12, 2018 | Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank passwo... |
| CVE-2018-15718 | — | — | 1.4% | Dec 12, 2018 | Open Dental before version 18.4 transmits the entire user database over the network when a remote unauthenticated user a... |
| CVE-2018-15717 | — | — | 0.5% | Dec 12, 2018 | Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes. |
| CVE-2018-20103 | — | — | 6.6% | Dec 12, 2018 | An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can tr... |
| CVE-2018-20102 | — | — | 4.3% | Dec 12, 2018 | An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing c... |
| CVE-2018-20101 | — | — | 0.8% | Dec 12, 2018 | The codection "Import users from CSV with meta" plugin before 1.12.1 for WordPress allows XSS via the value of a cell. |
| CVE-2018-1926 | MEDIUM | 4.3 | 1.2% | Dec 12, 2018 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site request forgery, cause... |
| CVE-2018-1901 | MEDIUM | 5 | 1.5% | Dec 12, 2018 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on th... |
| CVE-2018-1485 | LOW | 3.1 | 1.0% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful auth... |
| CVE-2018-1484 | LOW | 3.7 | 1.0% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens... |
| CVE-2018-1481 | LOW | 3.7 | 1.2% | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now