2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-1552MEDIUM5.5IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code...
CVE-2018-17912An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow re...
CVE-2018-17916CRITICAL9.8InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to...
CVE-2018-17914CRITICAL9.8InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to...
CVE-2018-18897MEDIUM6.5An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as...
CVE-2018-6909A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web applic...
CVE-2018-6908An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD ...
CVE-2018-6907A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch...
CVE-2018-6906A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and T...
CVE-2018-6012The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject ...
CVE-2018-6011The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2...
CVE-2018-18777Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp...
CVE-2018-18776Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (...
CVE-2018-18775Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (...
CVE-2018-18714RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker ...
CVE-2018-18695M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted...
CVE-2018-10587NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vu...
CVE-2018-10586NetGain Enterprise Manager (EM) is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities in versions be...
CVE-2018-3977HIGH8.8An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A speci...
CVE-2018-3947HIGH8.1An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US ...
CVE-2018-3928HIGH7.5An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D....
CVE-2018-3910HIGH8An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D....
CVE-2018-3900HIGH8.8An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D...
CVE-2018-14660MEDIUM6.5A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY x...
CVE-2018-7356MEDIUM5.6All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vul...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now