2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-0056MEDIUM6.5If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning funct...
CVE-2018-0055MEDIUM6.5Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP server in a Broadband E...
CVE-2018-0054MEDIUM6.5On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the manag...
CVE-2018-0053MEDIUM6.8An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allo...
CVE-2018-0052HIGH7.2If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can o...
CVE-2018-0051HIGH7.5A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allow...
CVE-2018-0050HIGH7.5An error handling vulnerability in Routing Protocols Daemon (RPD) of Juniper Networks Junos OS allows an attacker to cau...
CVE-2018-0049HIGH7.5A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to...
CVE-2018-0048HIGH7.5A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network b...
CVE-2018-0047HIGH8A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow auth...
CVE-2018-0046HIGH8.8A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the steal...
CVE-2018-0045HIGH8.8Receipt of a specific Draft-Rosen MVPN control packet may cause the routing protocol daemon (RPD) process to crash and r...
CVE-2018-0044CRITICAL9.8An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remot...
CVE-2018-0043HIGH8.8Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead t...
CVE-2018-17925Multiple instances of this vulnerability (Unsafe ActiveX Control Marked Safe For Scripting) have been identified in the ...
CVE-2018-13805A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-...
CVE-2018-13802A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged...
CVE-2018-13801A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp a...
CVE-2018-13800A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface c...
CVE-2018-18211PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
CVE-2018-18210XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.
CVE-2018-18209XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.
CVE-2018-18208Virtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.
CVE-2018-18207Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
CVE-2018-17919All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumente...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now