2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10569 | — | — | 0.9% | Aug 13, 2018 | An issue was discovered in Edimax EW-7438RPn Mini v2 before version 1.26. There is XSS in an SSID field. |
| CVE-2018-11770 | MEDIUM | 4.2 | 65.9% | Aug 13, 2018 | From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su... |
| CVE-2018-6414 | — | — | 2.5% | Aug 13, 2018 | A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially cr... |
| CVE-2018-5925 | — | — | 10.9% | Aug 13, 2018 | A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affe... |
| CVE-2018-5924 | — | — | 12.2% | Aug 13, 2018 | A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affe... |
| CVE-2018-13392 | — | — | 1.7% | Aug 13, 2018 | Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML... |
| CVE-2018-0714 | — | — | 2.3% | Aug 13, 2018 | Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 buil... |
| CVE-2018-3776 | MEDIUM | 5.3 | 1.3% | Aug 12, 2018 | Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being lo... |
| CVE-2018-3775 | HIGH | 8.8 | 1.2% | Aug 12, 2018 | Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentia... |
| CVE-2018-3774 | — | — | 3.8% | Aug 12, 2018 | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open ... |
| CVE-2018-3110 | — | — | 2.5% | Aug 10, 2018 | A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected ... |
| CVE-2018-3779 | — | — | 6.1% | Aug 10, 2018 | active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containin... |
| CVE-2018-11063 | — | — | 0.3% | Aug 10, 2018 | Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software instal... |
| CVE-2018-11048 | HIGH | 8.1 | 2.1% | Aug 10, 2018 | Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) v... |
| CVE-2018-14785 | — | — | 2.2% | Aug 10, 2018 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the devi... |
| CVE-2018-14784 | — | — | 1.0% | Aug 10, 2018 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable ... |
| CVE-2018-14783 | — | — | 0.7% | Aug 10, 2018 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forg... |
| CVE-2018-14782 | — | — | 1.6% | Aug 10, 2018 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access ... |
| CVE-2018-13341 | — | — | 3.6% | Aug 10, 2018 | Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for spe... |
| CVE-2018-10630 | — | — | 10.9% | Aug 10, 2018 | For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped wi... |
| CVE-2018-10626 | MEDIUM | 4.4 | 0.4% | Aug 10, 2018 | Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded... |
| CVE-2018-10622 | MEDIUM | 5.2 | 0.4% | Aug 10, 2018 | Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c... |
| CVE-2018-15191 | — | — | 1.1% | Aug 10, 2018 | PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript ... |
| CVE-2018-15190 | — | — | 0.5% | Aug 10, 2018 | PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field. |
| CVE-2018-7754 | — | — | 0.4% | Aug 10, 2018 | The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now