2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17292 | — | — | 1.2% | Sep 21, 2018 | An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the... |
| CVE-2018-17283 | — | — | 60.1% | Sep 21, 2018 | Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as de... |
| CVE-2018-17282 | — | — | 2.1% | Sep 20, 2018 | An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference. |
| CVE-2018-16752 | — | — | 42.7% | Sep 20, 2018 | LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST fi... |
| CVE-2018-16282 | — | — | 4.7% | Sep 20, 2018 | A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote atta... |
| CVE-2018-15832 | — | — | 3.7% | Sep 20, 2018 | upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User int... |
| CVE-2018-14592 | — | — | 3.1% | Sep 20, 2018 | The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 fo... |
| CVE-2018-6505 | HIGH | 7.5 | 2.5% | Sep 20, 2018 | A potential Unauthenticated File Download vulnerability has been identified in ArcSight Management Center (ArcMC) in all... |
| CVE-2018-6504 | HIGH | 8.8 | 0.6% | Sep 20, 2018 | A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in... |
| CVE-2018-6503 | MEDIUM | 6.5 | 1.1% | Sep 20, 2018 | A potential Access Control vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior... |
| CVE-2018-6502 | MEDIUM | 6.5 | 1.3% | Sep 20, 2018 | A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Cente... |
| CVE-2018-14829 | — | — | 16.1% | Sep 20, 2018 | Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to int... |
| CVE-2018-14827 | — | — | 3.8% | Sep 20, 2018 | Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally ... |
| CVE-2018-14821 | — | — | 4.5% | Sep 20, 2018 | Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated th... |
| CVE-2018-14796 | — | — | 1.1% | Sep 20, 2018 | Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot comm... |
| CVE-2018-6501 | — | — | 0.8% | Sep 20, 2018 | Potential security vulnerability of Insufficient Access Controls has been identified in ArcSight Management Center (ArcM... |
| CVE-2018-6500 | HIGH | 7.5 | 4.0% | Sep 20, 2018 | A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all ... |
| CVE-2018-3865 | HIGH | 8.8 | 1.8% | Sep 20, 2018 | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsu... |
| CVE-2018-3864 | HIGH | 8.8 | 1.8% | Sep 20, 2018 | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsu... |
| CVE-2018-1800 | MEDIUM | 5.1 | 0.3% | Sep 20, 2018 | IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive inf... |
| CVE-2018-1674 | MEDIUM | 6.3 | 1.7% | Sep 20, 2018 | IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote att... |
| CVE-2018-17255 | — | — | — | Sep 20, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-14014. Reason: This candidate is a reservation d... |
| CVE-2018-17254 | CRITICAL | 9.8 | 83.0% | Sep 20, 2018 | The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. |
| CVE-2018-5871 | — | — | 0.3% | Sep 20, 2018 | In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD ... |
| CVE-2018-5837 | — | — | 0.6% | Sep 20, 2018 | In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, S... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now