2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13823 | — | — | 1.9% | Aug 30, 2018 | An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below,... |
| CVE-2018-13821 | — | — | 2.7% | Aug 30, 2018 | A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to cond... |
| CVE-2018-13820 | — | — | 1.4% | Aug 30, 2018 | A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensit... |
| CVE-2018-13819 | — | — | 1.4% | Aug 30, 2018 | A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensit... |
| CVE-2018-16157 | — | — | 0.7% | Aug 30, 2018 | waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da... |
| CVE-2018-16131 | — | — | 3.1% | Aug 30, 2018 | The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.... |
| CVE-2018-14317 | — | — | 2.8% | Aug 30, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5... |
| CVE-2018-11616 | — | — | 4.9% | Aug 30, 2018 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.... |
| CVE-2018-11615 | — | — | 3.3% | Aug 30, 2018 | This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authenticatio... |
| CVE-2018-16158 | — | — | 34.9% | Aug 30, 2018 | Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different cus... |
| CVE-2018-16142 | — | — | 0.7% | Aug 30, 2018 | PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f f... |
| CVE-2018-16141 | — | — | 0.9% | Aug 30, 2018 | ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileControl... |
| CVE-2018-16140 | — | — | 1.4% | Aug 30, 2018 | A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the begi... |
| CVE-2018-16058 | — | — | 3.4% | Aug 30, 2018 | In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was ad... |
| CVE-2018-16056 | — | — | 3.4% | Aug 30, 2018 | In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash... |
| CVE-2018-16134 | — | — | 4.0% | Aug 29, 2018 | Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI. |
| CVE-2018-16133 | — | — | 39.3% | Aug 29, 2018 | Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI. |
| CVE-2018-16132 | — | — | 1.1% | Aug 29, 2018 | The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to chec... |
| CVE-2018-16115 | — | — | 1.2% | Aug 29, 2018 | Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error. A random number g... |
| CVE-2018-6599 | — | — | 0.3% | Aug 29, 2018 | An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices, allowing att... |
| CVE-2018-6598 | — | — | 0.3% | Aug 29, 2018 | An issue was discovered on Orbic Wonder Orbic/RC555L/RC555L:7.1.2/N2G47H/329100b:user/release-keys devices. Any app co-l... |
| CVE-2018-6597 | — | — | 0.5% | Aug 29, 2018 | The Alcatel A30 device with a build fingerprint of TCL/5046G/MICKEY6US:7.0/NRD90M/J63:user/release-keys contains a hidde... |
| CVE-2018-15912 | — | — | 0.8% | Aug 29, 2018 | An issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can ... |
| CVE-2018-15907 | — | — | 1.0% | Aug 29, 2018 | Technicolor (formerly RCA) TC8305C devices allow remote attackers to cause a denial of service (networking outage) via a... |
| CVE-2018-15562 | — | — | 1.0% | Aug 29, 2018 | CMS ISWEB 3.5.3 has XSS via the ordineRis, sezioneRicerca, or oggettiRicerca parameter to index.php. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now