2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-17081e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbi...
CVE-2018-16969Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message.
CVE-2018-16968Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.
CVE-2018-16364HIGH8.1A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execut...
CVE-2018-16152HIGH7.5In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the R...
CVE-2018-16151HIGH7.5In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the R...
CVE-2018-15836In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not veri...
CVE-2018-17556MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
CVE-2018-17555HIGH7.5The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /s...
CVE-2018-14823CRITICAL9.8Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may all...
CVE-2018-14819Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remot...
CVE-2018-14817Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote...
CVE-2018-14815Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may al...
CVE-2018-14813CRITICAL9.8Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allo...
CVE-2018-14811Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, w...
CVE-2018-14809Fuji Electric V-Server 4.0.3.0 and prior, A use after free vulnerability has been identified, which may allow remote cod...
CVE-2018-8856Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, w...
CVE-2018-8854Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or a...
CVE-2018-8852Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing ...
CVE-2018-8850Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowi...
CVE-2018-8848HIGH7.5Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permi...
CVE-2018-8846Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutr...
CVE-2018-8844Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently...
CVE-2018-8842Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical...
CVE-2018-14803Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vuln...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now