2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10569An issue was discovered in Edimax EW-7438RPn Mini v2 before version 1.26. There is XSS in an SSID field.
CVE-2018-11770MEDIUM4.2From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su...
CVE-2018-6414A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially cr...
CVE-2018-5925A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affe...
CVE-2018-5924A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affe...
CVE-2018-13392Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML...
CVE-2018-0714Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 buil...
CVE-2018-3776MEDIUM5.3Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being lo...
CVE-2018-3775HIGH8.8Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentia...
CVE-2018-3774Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open ...
CVE-2018-3110A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected ...
CVE-2018-3779active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containin...
CVE-2018-11063Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software instal...
CVE-2018-11048HIGH8.1Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) v...
CVE-2018-14785NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the devi...
CVE-2018-14784NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable ...
CVE-2018-14783NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forg...
CVE-2018-14782NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access ...
CVE-2018-13341Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for spe...
CVE-2018-10630For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped wi...
CVE-2018-10626MEDIUM4.4Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded...
CVE-2018-10622MEDIUM5.2Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c...
CVE-2018-15191PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript ...
CVE-2018-15190PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
CVE-2018-7754The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now