2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17081 | — | — | 0.6% | Sep 26, 2018 | e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbi... |
| CVE-2018-16969 | — | — | 1.1% | Sep 26, 2018 | Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. |
| CVE-2018-16968 | — | — | 1.1% | Sep 26, 2018 | Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. |
| CVE-2018-16364 | HIGH | 8.1 | 15.1% | Sep 26, 2018 | A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execut... |
| CVE-2018-16152 | HIGH | 7.5 | 1.9% | Sep 26, 2018 | In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the R... |
| CVE-2018-16151 | HIGH | 7.5 | 1.9% | Sep 26, 2018 | In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the R... |
| CVE-2018-15836 | — | — | 1.5% | Sep 26, 2018 | In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not veri... |
| CVE-2018-17556 | — | — | 0.6% | Sep 26, 2018 | MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action. |
| CVE-2018-17555 | HIGH | 7.5 | 2.0% | Sep 26, 2018 | The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /s... |
| CVE-2018-14823 | CRITICAL | 9.8 | 3.9% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may all... |
| CVE-2018-14819 | — | — | 3.6% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remot... |
| CVE-2018-14817 | — | — | 3.6% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote... |
| CVE-2018-14815 | — | — | 3.6% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, Several out-of-bounds write vulnerabilities have been identified, which may al... |
| CVE-2018-14813 | CRITICAL | 9.8 | 3.9% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allo... |
| CVE-2018-14811 | — | — | 3.6% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, w... |
| CVE-2018-14809 | — | — | 2.7% | Sep 26, 2018 | Fuji Electric V-Server 4.0.3.0 and prior, A use after free vulnerability has been identified, which may allow remote cod... |
| CVE-2018-8856 | — | — | 1.4% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, w... |
| CVE-2018-8854 | — | — | 2.5% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not properly restrict the size or a... |
| CVE-2018-8852 | — | — | 1.9% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing ... |
| CVE-2018-8850 | — | — | 3.8% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not validate input properly, allowi... |
| CVE-2018-8848 | HIGH | 7.5 | 2.0% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permi... |
| CVE-2018-8846 | — | — | 1.3% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software does not neutralize or incorrectly neutr... |
| CVE-2018-8844 | — | — | 0.9% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently... |
| CVE-2018-8842 | — | — | 0.6% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical... |
| CVE-2018-14803 | — | — | 1.7% | Sep 26, 2018 | Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vuln... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now