2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11404 | — | — | 2.3% | May 24, 2018 | DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter. |
| CVE-2018-11403 | — | — | 1.8% | May 24, 2018 | DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter. |
| CVE-2018-11402 | — | — | 0.2% | May 24, 2018 | SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PI... |
| CVE-2018-11401 | — | — | 0.3% | May 24, 2018 | In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker... |
| CVE-2018-11400 | — | — | 0.3% | May 24, 2018 | In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physicall... |
| CVE-2018-11399 | — | — | 0.2% | May 24, 2018 | SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentia... |
| CVE-2018-10428 | — | — | 2.0% | May 23, 2018 | ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulne... |
| CVE-2018-10654 | — | — | 1.2% | May 23, 2018 | There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befo... |
| CVE-2018-10653 | — | — | 6.8% | May 23, 2018 | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befor... |
| CVE-2018-10652 | — | — | 1.2% | May 23, 2018 | There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3. |
| CVE-2018-10651 | — | — | 0.7% | May 23, 2018 | There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-10650 | — | — | 0.8% | May 23, 2018 | There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-10649 | — | — | 0.7% | May 23, 2018 | There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. |
| CVE-2018-10648 | — | — | 1.2% | May 23, 2018 | There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. |
| CVE-2018-8898 | — | — | 13.3% | May 23, 2018 | A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B0... |
| CVE-2018-11231 | — | — | 9.1% | May 23, 2018 | In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential info... |
| CVE-2018-10357 | — | — | 73.9% | May 23, 2018 | A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to exe... |
| CVE-2018-10356 | — | — | 10.5% | May 23, 2018 | A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker ... |
| CVE-2018-10355 | — | — | 0.6% | May 23, 2018 | An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover ... |
| CVE-2018-10354 | — | — | 13.6% | May 23, 2018 | A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a rem... |
| CVE-2018-10353 | — | — | 1.4% | May 23, 2018 | A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote at... |
| CVE-2018-10352 | — | — | 2.2% | May 23, 2018 | A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL state... |
| CVE-2018-10351 | — | — | 3.7% | May 23, 2018 | A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL state... |
| CVE-2018-1193 | — | — | 1.1% | May 23, 2018 | Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers... |
| CVE-2018-1310 | — | — | 3.2% | May 23, 2018 | Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now