2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-3748 | — | — | 0.8% | Jul 3, 2018 | There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTM... |
| CVE-2018-3747 | — | — | 0.8% | Jul 3, 2018 | The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to... |
| CVE-2018-8036 | — | — | 4.8% | Jul 3, 2018 | In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite lo... |
| CVE-2018-13116 | — | — | 1.1% | Jul 3, 2018 | /user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table. |
| CVE-2018-13113 | HIGH | 7.5 | 1.3% | Jul 3, 2018 | The transfer and transferFrom functions of a smart contract implementation for Easy Trading Token (ETT), an Ethereum tok... |
| CVE-2018-13112 | — | — | 2.3% | Jul 3, 2018 | get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buff... |
| CVE-2018-11643 | — | — | 1.4% | Jul 3, 2018 | SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authentic... |
| CVE-2018-11642 | — | — | 0.5% | Jul 3, 2018 | Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS... |
| CVE-2018-11641 | — | — | 1.7% | Jul 3, 2018 | Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Di... |
| CVE-2018-11640 | — | — | 1.9% | Jul 3, 2018 | XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attac... |
| CVE-2018-11639 | — | — | 1.1% | Jul 3, 2018 | Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrat... |
| CVE-2018-11638 | — | — | 4.1% | Jul 3, 2018 | Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5... |
| CVE-2018-11637 | — | — | 2.1% | Jul 3, 2018 | Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote att... |
| CVE-2018-11636 | — | — | 0.6% | Jul 3, 2018 | Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 all... |
| CVE-2018-11635 | — | — | 2.0% | Jul 3, 2018 | Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php ... |
| CVE-2018-11634 | — | — | 0.4% | Jul 3, 2018 | Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local user... |
| CVE-2018-11052 | CRITICAL | 9.8 | 4.2% | Jul 3, 2018 | Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attac... |
| CVE-2018-11051 | HIGH | 7.5 | 2.6% | Jul 3, 2018 | RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA C... |
| CVE-2018-13106 | — | — | 0.7% | Jul 3, 2018 | ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI. |
| CVE-2018-13102 | — | — | 1.1% | Jul 3, 2018 | AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability. |
| CVE-2018-11316 | — | — | 1.3% | Jul 3, 2018 | The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can r... |
| CVE-2018-11314 | — | — | 1.7% | Jul 3, 2018 | The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result... |
| CVE-2018-7635 | — | — | 0.8% | Jul 3, 2018 | Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar wh... |
| CVE-2018-7787 | — | — | 1.1% | Jul 3, 2018 | In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validati... |
| CVE-2018-7786 | — | — | 0.8% | Jul 3, 2018 | In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exi... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now