2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-10701——An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script...
CVE-2018-10700——An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the...
CVE-2018-10699——An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that ...
CVE-2018-10696——An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to ...
CVE-2018-10695——An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send...
CVE-2018-10693——An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execu...
CVE-2018-10692——An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. ...
CVE-2018-10691——An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log ...
CVE-2018-19999——The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local...
CVE-2018-19860——Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecif...
CVE-2018-19802——aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.
CVE-2018-19801——aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.
CVE-2018-19800——aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.
CVE-2018-19465——Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php ...
CVE-2018-19462——admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that...
CVE-2018-19461——admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
CVE-2018-19452——A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF ...
CVE-2018-19451——A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when...
CVE-2018-5264——Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free ti...
CVE-2018-20135——Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of appl...
CVE-2018-20091——An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow...
CVE-2018-20014——In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin...
CVE-2018-6185——In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undel...
CVE-2018-5798——This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager.
CVE-2018-5265——Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credential...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now