2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13121RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and...
CVE-2018-9337The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and ...
CVE-2018-9335The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS...
CVE-2018-9334The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earli...
CVE-2018-9242The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earli...
CVE-2018-7636The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScri...
CVE-2018-3754Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability...
CVE-2018-3753The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the proto...
CVE-2018-3752The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the proto...
CVE-2018-3751The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the pro...
CVE-2018-3750The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototy...
CVE-2018-3749The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Ob...
CVE-2018-3748There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTM...
CVE-2018-3747The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to...
CVE-2018-8036In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite lo...
CVE-2018-13116/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.
CVE-2018-13112get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buff...
CVE-2018-11643SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authentic...
CVE-2018-11642Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS...
CVE-2018-11641Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Di...
CVE-2018-11640XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attac...
CVE-2018-11639Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrat...
CVE-2018-11638Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5...
CVE-2018-11637Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote att...
CVE-2018-11636Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 all...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now