2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18568MEDIUM5.9Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credentia...
CVE-2018-18567AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credentia...
CVE-2018-18566MEDIUM5.3The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive ph...
CVE-2018-18552ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss...
CVE-2018-18551ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, ...
CVE-2018-17923SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to...
CVE-2018-17921HIGH8.8SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair...
CVE-2018-17903CRITICAL9.1SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
CVE-2018-15751SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute ...
CVE-2018-15750Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remo...
CVE-2018-13342The server API in the Anda app relies on hardcoded credentials.
CVE-2018-9281An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the...
CVE-2018-9280An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. Th...
CVE-2018-9279An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page disp...
CVE-2018-18636XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.
CVE-2018-18635www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.0...
CVE-2018-18548ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi...
CVE-2018-18547Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the ...
CVE-2018-18517Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x befor...
CVE-2018-18476mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected datab...
CVE-2018-18014MEDIUM4.8* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands ...
CVE-2018-18013* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated i...
CVE-2018-14812An uncontrolled search path element (DLL Hijacking) vulnerability has been identified in Fuji Electric Energy Savings Es...
CVE-2018-12650Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe...
CVE-2018-11792In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential securi...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now