2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-8261Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d...
CVE-2018-15355Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware 3.5.30.1118.
CVE-2018-15354A Buffer Overflow exploited through web interface by remote attacker can cause denial of service in Kraftway 24F2XG Rout...
CVE-2018-15353A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG ...
CVE-2018-15352An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118.
CVE-2018-15351Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftwa...
CVE-2018-15350Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileg...
CVE-2018-3783A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in ...
CVE-2018-5547Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy lo...
CVE-2018-15122An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it pos...
CVE-2018-14567libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafte...
CVE-2018-13446An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authenticat...
CVE-2018-13435An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication ...
CVE-2018-13434An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID)...
CVE-2018-12256admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious fil...
CVE-2018-11511The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability...
CVE-2018-11509ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat...
CVE-2018-10140The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to sh...
CVE-2018-10139The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier...
CVE-2018-0428A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, ...
CVE-2018-0419A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unaut...
CVE-2018-0415A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Smal...
CVE-2018-0412A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Smal...
CVE-2018-0410A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow a...
CVE-2018-0386A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now