2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11635Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php ...
CVE-2018-11634Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local user...
CVE-2018-13106ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.
CVE-2018-13102AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.
CVE-2018-11316The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can r...
CVE-2018-11314The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result...
CVE-2018-7635Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar wh...
CVE-2018-7787In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validati...
CVE-2018-7786In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exi...
CVE-2018-7785In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authenticati...
CVE-2018-7784In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of...
CVE-2018-7783Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the D...
CVE-2018-7782In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authentic...
CVE-2018-7781In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sendin...
CVE-2018-7780In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer ...
CVE-2018-7779In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak an...
CVE-2018-7778In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may al...
CVE-2018-7777The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Ele...
CVE-2018-7776The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. Syst...
CVE-2018-7775Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-9960. Reason: This candidate is a duplicate of...
CVE-2018-7774The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prio...
CVE-2018-7773The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions pri...
CVE-2018-7772The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motio...
CVE-2018-7771The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions pr...
CVE-2018-7770The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prio...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now