2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0056 | MEDIUM | 6.5 | 0.6% | Oct 10, 2018 | If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning funct... |
| CVE-2018-0055 | MEDIUM | 6.5 | 0.6% | Oct 10, 2018 | Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP server in a Broadband E... |
| CVE-2018-0054 | MEDIUM | 6.5 | 0.6% | Oct 10, 2018 | On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the manag... |
| CVE-2018-0053 | MEDIUM | 6.8 | 0.5% | Oct 10, 2018 | An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allo... |
| CVE-2018-0052 | HIGH | 7.2 | 4.9% | Oct 10, 2018 | If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can o... |
| CVE-2018-0051 | HIGH | 7.5 | 1.6% | Oct 10, 2018 | A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allow... |
| CVE-2018-0050 | HIGH | 7.5 | 2.3% | Oct 10, 2018 | An error handling vulnerability in Routing Protocols Daemon (RPD) of Juniper Networks Junos OS allows an attacker to cau... |
| CVE-2018-0049 | HIGH | 7.5 | 2.2% | Oct 10, 2018 | A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to... |
| CVE-2018-0048 | HIGH | 7.5 | 2.9% | Oct 10, 2018 | A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network b... |
| CVE-2018-0047 | HIGH | 8 | 0.9% | Oct 10, 2018 | A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow auth... |
| CVE-2018-0046 | HIGH | 8.8 | 1.6% | Oct 10, 2018 | A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the steal... |
| CVE-2018-0045 | HIGH | 8.8 | 1.1% | Oct 10, 2018 | Receipt of a specific Draft-Rosen MVPN control packet may cause the routing protocol daemon (RPD) process to crash and r... |
| CVE-2018-0044 | CRITICAL | 9.8 | 1.3% | Oct 10, 2018 | An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remot... |
| CVE-2018-0043 | HIGH | 8.8 | 1.2% | Oct 10, 2018 | Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead t... |
| CVE-2018-17925 | — | — | 0.3% | Oct 10, 2018 | Multiple instances of this vulnerability (Unsafe ActiveX Control Marked Safe For Scripting) have been identified in the ... |
| CVE-2018-13805 | — | — | 1.5% | Oct 10, 2018 | A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-... |
| CVE-2018-13802 | — | — | 3.6% | Oct 10, 2018 | A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged... |
| CVE-2018-13801 | — | — | 2.7% | Oct 10, 2018 | A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp a... |
| CVE-2018-13800 | — | — | 0.6% | Oct 10, 2018 | A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface c... |
| CVE-2018-18211 | — | — | 0.9% | Oct 10, 2018 | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI. |
| CVE-2018-18210 | — | — | 0.9% | Oct 10, 2018 | XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter. |
| CVE-2018-18209 | — | — | 0.9% | Oct 10, 2018 | XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter. |
| CVE-2018-18208 | — | — | 0.7% | Oct 10, 2018 | Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI. |
| CVE-2018-18207 | — | — | 0.7% | Oct 10, 2018 | Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter. |
| CVE-2018-17919 | — | — | 1.0% | Oct 10, 2018 | All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumente... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now