2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-19493——An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x...
CVE-2018-14831——An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in t...
CVE-2018-20851——Helpy before 2.2.0 allows agents to edit admins.
CVE-2018-17147——Nagios XI before 5.5.4 has XSS in the auto login admin management page.
CVE-2018-14496——Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow...
CVE-2018-14495——Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device...
CVE-2018-14494——Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarificatio...
CVE-2018-12628——An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privil...
CVE-2018-12627——An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authori...
CVE-2018-12626——An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.
CVE-2018-12625——An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
CVE-2018-12623——An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.
CVE-2018-12622——An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.
CVE-2018-15738——An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulner...
CVE-2018-14833——Intuit Lacerte 2017 has Incorrect Access Control.
CVE-2018-16386——An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be ac...
CVE-2018-14733——The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS...
CVE-2018-14529——Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashe...
CVE-2018-14528——Invoxia NVX220 devices allow TELNET access as admin with a default password.
CVE-2018-12621——An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
CVE-2018-14027——Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
CVE-2018-20850——Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of ...
CVE-2018-14860——Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlie...
CVE-2018-14859——Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and...
CVE-2018-14865——Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not u...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now