2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13823An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below,...
CVE-2018-13821A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to cond...
CVE-2018-13820A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensit...
CVE-2018-13819A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensit...
CVE-2018-16157waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da...
CVE-2018-16131The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0....
CVE-2018-14317This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5...
CVE-2018-11616This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2....
CVE-2018-11615This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authenticatio...
CVE-2018-16158Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different cus...
CVE-2018-16142PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f f...
CVE-2018-16141ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileControl...
CVE-2018-16140A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the begi...
CVE-2018-16058In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was ad...
CVE-2018-16056In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash...
CVE-2018-16134Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
CVE-2018-16133Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
CVE-2018-16132The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to chec...
CVE-2018-16115Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error. A random number g...
CVE-2018-6599An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing att...
CVE-2018-6598An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices. Any app co-l...
CVE-2018-6597The Alcatel A30 device with a build fingerprint of TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys contains a hidde...
CVE-2018-15912An issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can ...
CVE-2018-15907Technicolor (formerly RCA) TC8305C devices allow remote attackers to cause a denial of service (networking outage) via a...
CVE-2018-15562CMS ISWEB 3.5.3 has XSS via the ordineRis, sezioneRicerca, or oggettiRicerca parameter to index.php.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now