2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11404DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
CVE-2018-11403DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
CVE-2018-11402SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PI...
CVE-2018-11401In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker...
CVE-2018-11400In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physicall...
CVE-2018-11399SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentia...
CVE-2018-10428ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulne...
CVE-2018-10654There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befo...
CVE-2018-10653There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befor...
CVE-2018-10652There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
CVE-2018-10651There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2018-10650There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2018-10649There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
CVE-2018-10648There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2018-8898A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B0...
CVE-2018-11231In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential info...
CVE-2018-10357A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to exe...
CVE-2018-10356A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker ...
CVE-2018-10355An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover ...
CVE-2018-10354A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a rem...
CVE-2018-10353A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote at...
CVE-2018-10352A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL state...
CVE-2018-10351A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL state...
CVE-2018-1193Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers...
CVE-2018-1310Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now