2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14864 | — | — | 1.2% | Jul 3, 2019 | Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through... |
| CVE-2018-14863 | — | — | 1.0% | Jul 3, 2019 | Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 al... |
| CVE-2018-14862 | — | — | 0.8% | Jul 3, 2019 | Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and e... |
| CVE-2018-14861 | — | — | 1.0% | Jul 3, 2019 | Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated user... |
| CVE-2018-14866 | — | — | 0.8% | Jul 3, 2019 | Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and... |
| CVE-2018-12250 | — | — | 1.6% | Jul 3, 2019 | An issue was discovered in Elite CMS Pro 2.01. In /admin/add_sidebar.php, the ?page= parameter is vulnerable to SQL inje... |
| CVE-2018-11686 | — | — | 49.8% | Jul 3, 2019 | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c... |
| CVE-2018-10986 | — | — | 0.5% | Jul 3, 2019 | OX Guard 2.8.0 has CSRF. |
| CVE-2018-11425 | — | — | 1.5% | Jul 3, 2019 | Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a differen... |
| CVE-2018-11424 | — | — | 1.4% | Jul 3, 2019 | There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a... |
| CVE-2018-11423 | — | — | 1.4% | Jul 3, 2019 | There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, diff... |
| CVE-2018-11422 | — | — | 1.0% | Jul 3, 2019 | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does no... |
| CVE-2018-11421 | — | — | 0.9% | Jul 3, 2019 | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not p... |
| CVE-2018-11420 | — | — | 1.5% | Jul 3, 2019 | There is Memory corruption in the web interface of Moxa OnCell G3100-HSPA Series version 1.5 Build 17042015 and prio,r a... |
| CVE-2018-11317 | — | — | 0.9% | Jul 3, 2019 | Subrion CMS before 4.1.4 has XSS. |
| CVE-2018-11227 | — | — | 4.8% | Jul 3, 2019 | Monstra CMS 3.0.4 and earlier has XSS via index.php. |
| CVE-2018-11215 | — | — | 2.4% | Jul 3, 2019 | Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified at... |
| CVE-2018-11427 | — | — | 0.6% | Jul 3, 2019 | CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, w... |
| CVE-2018-11426 | — | — | 1.8% | Jul 3, 2019 | A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and p... |
| CVE-2018-20849 | — | — | 1.0% | Jun 30, 2019 | Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI. |
| CVE-2018-20848 | — | — | 0.8% | Jun 30, 2019 | Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by... |
| CVE-2018-20814 | — | — | 1.6% | Jun 28, 2019 | An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Pol... |
| CVE-2018-20813 | — | — | 3.1% | Jun 28, 2019 | An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2. |
| CVE-2018-20812 | — | — | 1.1% | Jun 28, 2019 | An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement w... |
| CVE-2018-20811 | — | — | 2.1% | Jun 28, 2019 | A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now