2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16728feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new.
CVE-2018-16727razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
CVE-2018-16726razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
CVE-2018-16605MEDIUM5.4D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
CVE-2018-16389e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.
CVE-2018-16388e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php ...
CVE-2018-15834In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/a...
CVE-2018-15502Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidentia...
CVE-2018-13412An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable com...
CVE-2018-13411An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window runni...
CVE-2018-7939Huawei smart phones G9 Lite, Honor 5A, Honor 6X, Honor 8 with the versions before VNS-L53C605B120CUSTC605D103, the versi...
CVE-2018-7923Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vul...
CVE-2018-7922Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vul...
CVE-2018-7921Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjace...
CVE-2018-7906Some Huawei smart phones with software of Leland-AL00 8.0.0.114(C636), Leland-AL00A 8.0.0.171(C00) have a denial of serv...
CVE-2018-6924In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient valida...
CVE-2018-3885HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re...
CVE-2018-3884HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re...
CVE-2018-3883HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re...
CVE-2018-3882HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web re...
CVE-2018-1773MEDIUM4.3IBM Datacap Fastdoc Capture 9.1.1, 9.1.3, and 9.1.4 could allow an authenticated user to bypass future authentication me...
CVE-2018-13807A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCA...
CVE-2018-13806A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists i...
CVE-2018-13799A vulnerability has been identified in SIMATIC WinCC OA V3.14 and prior (All versions < V3.14-P021). Improper access con...
CVE-2018-16950Inteno DG400 WU7U_ELION3.11.6-170614_1328 devices allow remote attackers to cause a denial of service (connectivity loss...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now