2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-17292An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the...
CVE-2018-17283Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as de...
CVE-2018-17282An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
CVE-2018-16752LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST fi...
CVE-2018-16282A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote atta...
CVE-2018-15832upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User int...
CVE-2018-14592The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 fo...
CVE-2018-6505HIGH7.5A potential Unauthenticated File Download vulnerability has been identified in ArcSight Management Center (ArcMC) in all...
CVE-2018-6504HIGH8.8A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in...
CVE-2018-6503MEDIUM6.5A potential Access Control vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior...
CVE-2018-6502MEDIUM6.5A potential Reflected Cross-Site Scripting (XSS) Security vulnerability has been identified in ArcSight Management Cente...
CVE-2018-14829Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to int...
CVE-2018-14827Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally ...
CVE-2018-14821Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated th...
CVE-2018-14796Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot comm...
CVE-2018-6501Potential security vulnerability of Insufficient Access Controls has been identified in ArcSight Management Center (ArcM...
CVE-2018-6500HIGH7.5A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all ...
CVE-2018-3865HIGH8.8An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsu...
CVE-2018-3864HIGH8.8An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsu...
CVE-2018-1800MEDIUM5.1IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive inf...
CVE-2018-1674MEDIUM6.3IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection. A remote att...
CVE-2018-17255Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-14014. Reason: This candidate is a reservation d...
CVE-2018-17254CRITICAL9.8The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
CVE-2018-5871In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, SD 210/SD ...
CVE-2018-5837In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, S...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now