2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15745 | — | — | 97.7% | Aug 30, 2018 | Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F... |
| CVE-2018-15480 | — | — | 1.0% | Aug 30, 2018 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W... |
| CVE-2018-15479 | — | — | 0.8% | Aug 30, 2018 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W... |
| CVE-2018-15478 | — | — | 0.9% | Aug 30, 2018 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W... |
| CVE-2018-15477 | — | — | 1.6% | Aug 30, 2018 | myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS c... |
| CVE-2018-15476 | — | — | 0.8% | Aug 30, 2018 | An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, W... |
| CVE-2018-14903 | — | — | 0.5% | Aug 30, 2018 | EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote a... |
| CVE-2018-14902 | — | — | 1.2% | Aug 30, 2018 | The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access. This allow... |
| CVE-2018-14901 | — | — | 1.1% | Aug 30, 2018 | The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote an... |
| CVE-2018-14900 | — | — | 1.1% | Aug 30, 2018 | On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print job... |
| CVE-2018-14899 | — | — | 0.7% | Aug 30, 2018 | On the EPSON WF-2750 printer with firmware JP02I2, the Web interface AirPrint Setup page is vulnerable to HTML Injection... |
| CVE-2018-11720 | — | — | 1.7% | Aug 30, 2018 | Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directory Traversal. |
| CVE-2018-11719 | — | — | 0.8% | Aug 30, 2018 | Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE. |
| CVE-2018-11718 | — | — | 0.5% | Aug 30, 2018 | Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF. |
| CVE-2018-16159 | — | — | 49.9% | Aug 30, 2018 | The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/ad... |
| CVE-2018-15691 | — | — | 16.8% | Aug 30, 2018 | Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows atta... |
| CVE-2018-13826 | — | — | 1.8% | Aug 30, 2018 | An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below,... |
| CVE-2018-13825 | — | — | 0.9% | Aug 30, 2018 | Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and b... |
| CVE-2018-13824 | — | — | 1.8% | Aug 30, 2018 | Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2... |
| CVE-2018-13823 | — | — | 1.9% | Aug 30, 2018 | An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below,... |
| CVE-2018-13822 | HIGH | 7.5 | 1.3% | Aug 30, 2018 | Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, all... |
| CVE-2018-13821 | — | — | 2.7% | Aug 30, 2018 | A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to cond... |
| CVE-2018-13820 | — | — | 1.4% | Aug 30, 2018 | A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensit... |
| CVE-2018-13819 | — | — | 1.4% | Aug 30, 2018 | A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensit... |
| CVE-2018-16157 | — | — | 0.7% | Aug 30, 2018 | waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing da... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now