2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-20810Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connec...
CVE-2018-20809A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and ...
CVE-2018-20808An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header s...
CVE-2018-20807An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before ...
CVE-2018-17560The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS...
CVE-2018-17170Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remot...
CVE-2018-14918LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.
CVE-2018-14916LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
CVE-2018-14887Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterpri...
CVE-2018-14886The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable...
CVE-2018-14885Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and ...
CVE-2018-14868Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenti...
CVE-2018-14867Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 ...
CVE-2018-15519Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
CVE-2018-14919LOYTEC LGATE-902 6.3.2 devices allow XSS.
CVE-2018-15520Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
CVE-2018-15555On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and pa...
CVE-2018-6177Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin d...
CVE-2018-6176Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker wh...
CVE-2018-6171Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a...
CVE-2018-6168Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially ...
CVE-2018-6161Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same...
CVE-2018-6159Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obt...
CVE-2018-6157Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap co...
CVE-2018-6155Incorrect handling of frames in the VP8 parser in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to poten...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now