2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15326 | — | — | 0.6% | Oct 31, 2018 | In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth a... |
| CVE-2018-15325 | — | — | 1.0% | Oct 31, 2018 | In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may leak a small amount of ... |
| CVE-2018-15324 | — | — | 1.3% | Oct 31, 2018 | On BIG-IP APM 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, TMM may restart when processing a specially crafted request with APM p... |
| CVE-2018-15323 | — | — | 1.1% | Oct 31, 2018 | On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, in certain circumstances, when processing traffic through a Virtual Server... |
| CVE-2018-15322 | — | — | 1.1% | Oct 31, 2018 | On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Manag... |
| CVE-2018-15321 | — | — | 0.9% | Oct 31, 2018 | When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Man... |
| CVE-2018-15320 | — | — | 1.3% | Oct 31, 2018 | On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for ... |
| CVE-2018-15319 | — | — | 1.9% | Oct 31, 2018 | On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual servers with an HTTP ... |
| CVE-2018-15318 | — | — | 1.3% | Oct 31, 2018 | In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal whil... |
| CVE-2018-15317 | — | — | 1.4% | Oct 31, 2018 | In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.2.1-11.6.3.2, an attacker sending specially crafted ... |
| CVE-2018-1851 | HIGH | 7.3 | 3.9% | Oct 31, 2018 | IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the s... |
| CVE-2018-18869 | — | — | 3.7% | Oct 31, 2018 | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php file... |
| CVE-2018-18868 | — | — | 0.7% | Oct 31, 2018 | No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter... |
| CVE-2018-18867 | — | — | 1.5% | Oct 31, 2018 | An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue... |
| CVE-2018-18854 | — | — | 1.9% | Oct 31, 2018 | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) bec... |
| CVE-2018-18853 | — | — | 1.9% | Oct 31, 2018 | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) bec... |
| CVE-2018-18850 | — | — | 12.5% | Oct 31, 2018 | In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment ... |
| CVE-2018-8858 | — | — | 1.2% | Oct 30, 2018 | If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may a... |
| CVE-2018-17933 | — | — | 1.2% | Oct 30, 2018 | VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User a... |
| CVE-2018-17931 | — | — | 0.4% | Oct 30, 2018 | If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be af... |
| CVE-2018-16469 | HIGH | 7.5 | 1.7% | Oct 30, 2018 | The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Objec... |
| CVE-2018-16468 | — | — | 0.9% | Oct 30, 2018 | In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG elem... |
| CVE-2018-16467 | — | — | 1.1% | Oct 30, 2018 | A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file passwo... |
| CVE-2018-16466 | — | — | 1.0% | Oct 30, 2018 | Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting acces... |
| CVE-2018-16465 | — | — | 0.8% | Oct 30, 2018 | Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now