2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11635 | — | — | 2.0% | Jul 3, 2018 | Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php ... |
| CVE-2018-11634 | — | — | 0.4% | Jul 3, 2018 | Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local user... |
| CVE-2018-13106 | — | — | 0.7% | Jul 3, 2018 | ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI. |
| CVE-2018-13102 | — | — | 1.1% | Jul 3, 2018 | AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability. |
| CVE-2018-11316 | — | — | 1.3% | Jul 3, 2018 | The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can r... |
| CVE-2018-11314 | — | — | 1.7% | Jul 3, 2018 | The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result... |
| CVE-2018-7635 | — | — | 0.8% | Jul 3, 2018 | Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar wh... |
| CVE-2018-7787 | — | — | 1.1% | Jul 3, 2018 | In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validati... |
| CVE-2018-7786 | — | — | 0.8% | Jul 3, 2018 | In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exi... |
| CVE-2018-7785 | — | — | 3.1% | Jul 3, 2018 | In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authenticati... |
| CVE-2018-7784 | — | — | 2.3% | Jul 3, 2018 | In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of... |
| CVE-2018-7783 | — | — | 1.6% | Jul 3, 2018 | Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the D... |
| CVE-2018-7782 | — | — | 0.8% | Jul 3, 2018 | In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authentic... |
| CVE-2018-7781 | — | — | 0.6% | Jul 3, 2018 | In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sendin... |
| CVE-2018-7780 | — | — | 1.2% | Jul 3, 2018 | In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer ... |
| CVE-2018-7779 | — | — | 1.4% | Jul 3, 2018 | In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak an... |
| CVE-2018-7778 | — | — | 2.1% | Jul 3, 2018 | In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may al... |
| CVE-2018-7777 | — | — | 31.8% | Jul 3, 2018 | The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Ele... |
| CVE-2018-7776 | — | — | 0.7% | Jul 3, 2018 | The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. Syst... |
| CVE-2018-7775 | — | — | — | Jul 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-9960. Reason: This candidate is a duplicate of... |
| CVE-2018-7774 | — | — | 1.0% | Jul 3, 2018 | The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prio... |
| CVE-2018-7773 | — | — | 1.0% | Jul 3, 2018 | The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions pri... |
| CVE-2018-7772 | — | — | 1.0% | Jul 3, 2018 | The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motio... |
| CVE-2018-7771 | — | — | 1.4% | Jul 3, 2018 | The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions pr... |
| CVE-2018-7770 | — | — | 1.3% | Jul 3, 2018 | The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prio... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now