2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7572 | — | — | 0.4% | Sep 12, 2018 | Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can al... |
| CVE-2018-16729 | — | — | 0.6% | Sep 12, 2018 | Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage u... |
| CVE-2018-16728 | — | — | 0.6% | Sep 12, 2018 | feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new. |
| CVE-2018-16727 | — | — | 0.6% | Sep 12, 2018 | razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. |
| CVE-2018-16726 | — | — | 0.6% | Sep 12, 2018 | razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. |
| CVE-2018-16389 | — | — | 1.1% | Sep 12, 2018 | e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter. |
| CVE-2018-16388 | — | — | 2.2% | Sep 12, 2018 | e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php ... |
| CVE-2018-15834 | — | — | 1.0% | Sep 12, 2018 | In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/a... |
| CVE-2018-15502 | — | — | 1.3% | Sep 12, 2018 | Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidentia... |
| CVE-2018-13412 | — | — | 0.5% | Sep 12, 2018 | An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable com... |
| CVE-2018-13411 | — | — | 3.5% | Sep 12, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window runni... |
| CVE-2018-7939 | — | — | 0.2% | Sep 12, 2018 | Huawei smart phones G9 Lite, Honor 5A, Honor 6X, Honor 8 with the versions before VNS-L53C605B120CUSTC605D103, the versi... |
| CVE-2018-7923 | — | — | 1.0% | Sep 12, 2018 | Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vul... |
| CVE-2018-7922 | — | — | 1.0% | Sep 12, 2018 | Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vul... |
| CVE-2018-7921 | — | — | 13.2% | Sep 12, 2018 | Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjace... |
| CVE-2018-7906 | — | — | 0.6% | Sep 12, 2018 | Some Huawei smart phones with software of Leland-AL00 8.0.0.114(C636), Leland-AL00A 8.0.0.171(C00) have a denial of serv... |
| CVE-2018-6924 | — | — | 0.4% | Sep 12, 2018 | In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient valida... |
| CVE-2018-13807 | — | — | 4.2% | Sep 12, 2018 | A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCA... |
| CVE-2018-13806 | — | — | 1.4% | Sep 12, 2018 | A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists i... |
| CVE-2018-13799 | — | — | 2.3% | Sep 12, 2018 | A vulnerability has been identified in SIMATIC WinCC OA V3.14 and prior (All versions < V3.14-P021). Improper access con... |
| CVE-2018-16950 | — | — | 0.5% | Sep 12, 2018 | Inteno DG400 WU7U_ELION3.11.6-170614_1328 devices allow remote attackers to cause a denial of service (connectivity loss... |
| CVE-2018-16951 | — | — | 0.8% | Sep 12, 2018 | xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to C... |
| CVE-2018-16949 | — | — | 3.1% | Sep 12, 2018 | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables ... |
| CVE-2018-16948 | — | — | 2.0% | Sep 12, 2018 | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initi... |
| CVE-2018-16947 | — | — | 2.6% | Sep 12, 2018 | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accep... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now