2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16586 | — | — | 1.5% | Sep 28, 2018 | In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker coul... |
| CVE-2018-16277 | — | — | 0.6% | Sep 28, 2018 | The Image Import function in XWiki through 10.7 has XSS. |
| CVE-2018-14957 | — | — | 1.6% | Sep 28, 2018 | CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php... |
| CVE-2018-14956 | — | — | 2.6% | Sep 28, 2018 | CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the applica... |
| CVE-2018-14037 | — | — | 1.2% | Sep 28, 2018 | Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbit... |
| CVE-2018-14824 | — | — | 2.0% | Sep 27, 2018 | Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be ... |
| CVE-2018-7109 | — | — | 1.0% | Sep 27, 2018 | HPE has addressed a remote arbitrary file modification vulnerability in HPE enhanced Internet Usage Manager (eIUM) v9.0F... |
| CVE-2018-7108 | — | — | 2.5% | Sep 27, 2018 | HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote auth... |
| CVE-2018-7107 | — | — | 0.9% | Sep 27, 2018 | A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. ... |
| CVE-2018-7106 | — | — | — | Sep 27, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-7105 | — | — | 4.1% | Sep 27, 2018 | A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lig... |
| CVE-2018-7104 | — | — | 8.9% | Sep 27, 2018 | A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manage... |
| CVE-2018-7103 | — | — | 8.9% | Sep 27, 2018 | A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manage... |
| CVE-2018-7102 | — | — | 2.9% | Sep 27, 2018 | A security vulnerability in HPE Intelligent Management Center (iMC) PLAT E0506P09, createFabricAutoCfgFile could be remo... |
| CVE-2018-7101 | — | — | 7.1% | Sep 27, 2018 | A potential remote denial of service security vulnerability has been identified in HPE Integrated Lights Out 4 prior to ... |
| CVE-2018-17570 | — | — | 1.8% | Sep 26, 2018 | utils/ut_ws_svr.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. |
| CVE-2018-17569 | — | — | 1.7% | Sep 26, 2018 | network/nw_buf.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. |
| CVE-2018-17568 | — | — | 1.8% | Sep 26, 2018 | utils/ut_rpc.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. |
| CVE-2018-17411 | — | — | 1.9% | Sep 26, 2018 | An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20. |
| CVE-2018-17316 | — | — | 1.0% | Sep 26, 2018 | On the RICOH MP C6003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ... |
| CVE-2018-17315 | — | — | 1.0% | Sep 26, 2018 | On the RICOH MP C2003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ... |
| CVE-2018-17314 | — | — | 1.0% | Sep 26, 2018 | On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of a... |
| CVE-2018-17313 | — | — | 2.3% | Sep 26, 2018 | On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a... |
| CVE-2018-17312 | — | — | 1.0% | Sep 26, 2018 | On the RICOH Aficio MP 301 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of ad... |
| CVE-2018-17311 | — | — | 1.0% | Sep 26, 2018 | On the RICOH MP C6503 Plus printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of ad... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now