2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7102 | — | — | 2.9% | Sep 27, 2018 | A security vulnerability in HPE Intelligent Management Center (iMC) PLAT E0506P09, createFabricAutoCfgFile could be remo... |
| CVE-2018-7101 | — | — | 7.1% | Sep 27, 2018 | A potential remote denial of service security vulnerability has been identified in HPE Integrated Lights Out 4 prior to ... |
| CVE-2018-17570 | — | — | 1.8% | Sep 26, 2018 | utils/ut_ws_svr.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. |
| CVE-2018-17569 | — | — | 1.7% | Sep 26, 2018 | network/nw_buf.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. |
| CVE-2018-17568 | — | — | 1.8% | Sep 26, 2018 | utils/ut_rpc.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. |
| CVE-2018-17411 | — | — | 1.9% | Sep 26, 2018 | An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20. |
| CVE-2018-17316 | — | — | 1.0% | Sep 26, 2018 | On the RICOH MP C6003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ... |
| CVE-2018-17315 | — | — | 1.0% | Sep 26, 2018 | On the RICOH MP C2003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ... |
| CVE-2018-17314 | — | — | 1.0% | Sep 26, 2018 | On the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of a... |
| CVE-2018-17313 | — | — | 2.3% | Sep 26, 2018 | On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a... |
| CVE-2018-17312 | — | — | 1.0% | Sep 26, 2018 | On the RICOH Aficio MP 301 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of ad... |
| CVE-2018-17311 | — | — | 1.0% | Sep 26, 2018 | On the RICOH MP C6503 Plus printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of ad... |
| CVE-2018-17310 | — | — | 2.3% | Sep 26, 2018 | On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add... |
| CVE-2018-17309 | — | — | 1.0% | Sep 26, 2018 | On the RICOH MP C406Z printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ... |
| CVE-2018-16713 | — | — | 1.9% | Sep 26, 2018 | IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier v... |
| CVE-2018-16712 | — | — | 1.3% | Sep 26, 2018 | IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier v... |
| CVE-2018-16711 | — | — | 2.0% | Sep 26, 2018 | IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier v... |
| CVE-2018-16588 | — | — | 0.3% | Sep 26, 2018 | Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through ... |
| CVE-2018-16055 | — | — | 11.2% | Sep 26, 2018 | An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense ... |
| CVE-2018-15531 | — | — | 27.9% | Sep 26, 2018 | JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. |
| CVE-2018-14327 | — | — | 4.4% | Sep 26, 2018 | The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before ... |
| CVE-2018-17566 | — | — | 1.5% | Sep 26, 2018 | In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be cont... |
| CVE-2018-17410 | CRITICAL | 9.8 | 1.7% | Sep 26, 2018 | Horus CMS allows SQL Injection, as demonstrated by a request to the /busca or /home URI. |
| CVE-2018-17365 | HIGH | 7.5 | 2.1% | Sep 26, 2018 | SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter. |
| CVE-2018-17215 | — | — | 0.6% | Sep 26, 2018 | An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and p... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now