2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18568 | MEDIUM | 5.9 | 0.7% | Oct 24, 2018 | Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credentia... |
| CVE-2018-18567 | — | — | 1.2% | Oct 24, 2018 | AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credentia... |
| CVE-2018-18566 | MEDIUM | 5.3 | 2.8% | Oct 24, 2018 | The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive ph... |
| CVE-2018-18552 | — | — | 2.7% | Oct 24, 2018 | ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss... |
| CVE-2018-18551 | — | — | 1.1% | Oct 24, 2018 | ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, ... |
| CVE-2018-17923 | — | — | 0.3% | Oct 24, 2018 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to... |
| CVE-2018-17921 | HIGH | 8.8 | 0.7% | Oct 24, 2018 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair... |
| CVE-2018-17903 | CRITICAL | 9.1 | 1.6% | Oct 24, 2018 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery. |
| CVE-2018-15751 | — | — | 5.2% | Oct 24, 2018 | SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute ... |
| CVE-2018-15750 | — | — | 4.2% | Oct 24, 2018 | Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remo... |
| CVE-2018-13342 | — | — | 1.1% | Oct 24, 2018 | The server API in the Anda app relies on hardcoded credentials. |
| CVE-2018-9281 | — | — | 0.4% | Oct 24, 2018 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the... |
| CVE-2018-9280 | — | — | 1.0% | Oct 24, 2018 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. Th... |
| CVE-2018-9279 | — | — | 1.0% | Oct 24, 2018 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page disp... |
| CVE-2018-18636 | — | — | 1.3% | Oct 24, 2018 | XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter. |
| CVE-2018-18635 | — | — | 0.9% | Oct 24, 2018 | www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.0... |
| CVE-2018-18548 | — | — | 3.6% | Oct 24, 2018 | ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi... |
| CVE-2018-18547 | — | — | 1.1% | Oct 24, 2018 | Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the ... |
| CVE-2018-18517 | — | — | 0.8% | Oct 24, 2018 | Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x befor... |
| CVE-2018-18476 | — | — | 1.8% | Oct 24, 2018 | mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected datab... |
| CVE-2018-18014 | MEDIUM | 4.8 | 0.5% | Oct 24, 2018 | * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands ... |
| CVE-2018-18013 | — | — | 2.9% | Oct 24, 2018 | * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated i... |
| CVE-2018-14812 | — | — | 1.1% | Oct 24, 2018 | An uncontrolled search path element (DLL Hijacking) vulnerability has been identified in Fuji Electric Energy Savings Es... |
| CVE-2018-12650 | — | — | 2.6% | Oct 24, 2018 | Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSe... |
| CVE-2018-11792 | — | — | 2.5% | Oct 24, 2018 | In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential securi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now