2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-8261 | — | — | — | Aug 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d... |
| CVE-2018-15355 | — | — | 0.8% | Aug 17, 2018 | Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware 3.5.30.1118. |
| CVE-2018-15354 | — | — | 2.1% | Aug 17, 2018 | A Buffer Overflow exploited through web interface by remote attacker can cause denial of service in Kraftway 24F2XG Rout... |
| CVE-2018-15353 | — | — | 7.7% | Aug 17, 2018 | A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG ... |
| CVE-2018-15352 | — | — | 1.4% | Aug 17, 2018 | An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118. |
| CVE-2018-15351 | — | — | 2.0% | Aug 17, 2018 | Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftwa... |
| CVE-2018-15350 | — | — | 4.7% | Aug 17, 2018 | Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileg... |
| CVE-2018-3783 | — | — | 3.8% | Aug 17, 2018 | A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in ... |
| CVE-2018-5547 | — | — | 0.3% | Aug 17, 2018 | Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy lo... |
| CVE-2018-15122 | — | — | 1.2% | Aug 16, 2018 | An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it pos... |
| CVE-2018-14567 | — | — | 4.3% | Aug 16, 2018 | libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafte... |
| CVE-2018-13446 | — | — | 0.4% | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authenticat... |
| CVE-2018-13435 | — | — | 0.4% | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication ... |
| CVE-2018-13434 | — | — | 0.4% | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID)... |
| CVE-2018-12256 | — | — | 2.6% | Aug 16, 2018 | admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious fil... |
| CVE-2018-11511 | — | — | 11.2% | Aug 16, 2018 | The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability... |
| CVE-2018-11509 | — | — | 12.6% | Aug 16, 2018 | ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat... |
| CVE-2018-10140 | — | — | 1.9% | Aug 16, 2018 | The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to sh... |
| CVE-2018-10139 | — | — | 1.5% | Aug 16, 2018 | The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier... |
| CVE-2018-0428 | — | — | 0.4% | Aug 15, 2018 | A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, ... |
| CVE-2018-0419 | — | — | 2.8% | Aug 15, 2018 | A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unaut... |
| CVE-2018-0415 | — | — | 0.6% | Aug 15, 2018 | A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Smal... |
| CVE-2018-0412 | — | — | 0.3% | Aug 15, 2018 | A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Smal... |
| CVE-2018-0410 | — | — | 4.1% | Aug 15, 2018 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow a... |
| CVE-2018-0386 | — | — | 1.8% | Aug 15, 2018 | A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now