2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-15745Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F...
CVE-2018-15480An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W...
CVE-2018-15479An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W...
CVE-2018-15478An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W...
CVE-2018-15477myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS c...
CVE-2018-15476An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W...
CVE-2018-14903EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote a...
CVE-2018-14902The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access. This allow...
CVE-2018-14901The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote an...
CVE-2018-14900On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print job...
CVE-2018-14899On the EPSON WF-2750 printer with firmware JP02I2, the Web interface AirPrint Setup page is vulnerable to HTML Injection...
CVE-2018-11720Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directory Traversal.
CVE-2018-11719Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE.
CVE-2018-11718Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF.
CVE-2018-16159The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/ad...
CVE-2018-15691Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows atta...
CVE-2018-13826An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below,...
CVE-2018-13825Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and b...
CVE-2018-13824Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2...
CVE-2018-13823An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below,...
CVE-2018-13822HIGH7.5Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, all...
CVE-2018-13821A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to cond...
CVE-2018-13820A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensit...
CVE-2018-13819A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensit...
CVE-2018-16157waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now