2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17310 | — | — | 2.3% | Sep 26, 2018 | On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add... |
| CVE-2018-17309 | — | — | 1.0% | Sep 26, 2018 | On the RICOH MP C406Z printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ... |
| CVE-2018-16713 | — | — | 1.9% | Sep 26, 2018 | IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier v... |
| CVE-2018-16712 | — | — | 1.3% | Sep 26, 2018 | IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier v... |
| CVE-2018-16711 | — | — | 2.0% | Sep 26, 2018 | IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier v... |
| CVE-2018-16588 | — | — | 0.3% | Sep 26, 2018 | Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through ... |
| CVE-2018-16055 | — | — | 11.2% | Sep 26, 2018 | An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense ... |
| CVE-2018-15531 | — | — | 27.9% | Sep 26, 2018 | JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. |
| CVE-2018-14327 | — | — | 4.4% | Sep 26, 2018 | The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before ... |
| CVE-2018-17566 | — | — | 1.5% | Sep 26, 2018 | In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be cont... |
| CVE-2018-17215 | — | — | 0.6% | Sep 26, 2018 | An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and p... |
| CVE-2018-17081 | — | — | 0.6% | Sep 26, 2018 | e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbi... |
| CVE-2018-16969 | — | — | 1.1% | Sep 26, 2018 | Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. |
| CVE-2018-16968 | — | — | 1.1% | Sep 26, 2018 | Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. |
| CVE-2018-15836 | — | — | 1.5% | Sep 26, 2018 | In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not veri... |
| CVE-2018-17556 | — | — | 0.6% | Sep 26, 2018 | MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action. |
| CVE-2018-14819 | — | — | 3.6% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remot... |
| CVE-2018-14817 | — | — | 3.6% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote... |
| CVE-2018-14815 | — | — | 3.6% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may al... |
| CVE-2018-14811 | — | — | 3.6% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, w... |
| CVE-2018-14809 | — | — | 2.7% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, A use after free vulnerability has been identified, which may allow remote cod... |
| CVE-2018-8856 | — | — | 1.4% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, w... |
| CVE-2018-8854 | — | — | 2.5% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or a... |
| CVE-2018-8852 | — | — | 1.9% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing ... |
| CVE-2018-8850 | — | — | 3.8% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now