2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-11785Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to injec...
CVE-2018-15442HIGH7.8A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, loca...
CVE-2018-11804HIGH7.5Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to sp...
CVE-2018-17935HIGH8.1All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and r...
CVE-2018-1541MEDIUM5.4IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2018-7432Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light...
CVE-2018-7431Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13...
CVE-2018-7429Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6....
CVE-2018-7427Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6....
CVE-2018-18475Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
CVE-2018-18467An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing o...
CVE-2018-18437In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc paramete...
CVE-2018-17968A gambling smart contract implementation for RuletkaIo, an Ethereum gambling game, generates a random value that is pred...
CVE-2018-17877A lottery smart contract implementation for Greedy 599, an Ethereum gambling game, generates a random value that is pred...
CVE-2018-17873An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 ...
CVE-2018-17448An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10....
CVE-2018-17447An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before...
CVE-2018-17446A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 1...
CVE-2018-17445A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x befo...
CVE-2018-17444A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x be...
CVE-2018-16235Telligent Community 6.x, 7.x, 8.x, 9.x before 9.2.10.11796, 10.1.x before 10.1.10.11792, and 10.2.x before 10.2.3.4725 h...
CVE-2018-16226A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could a...
CVE-2018-15497The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality....
CVE-2018-12901A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an...
CVE-2018-18628An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStrea...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now