2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-10701An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run script...
CVE-2018-10700An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the...
CVE-2018-10699An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that ...
CVE-2018-10696An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to ...
CVE-2018-10695An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send...
CVE-2018-10693An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execu...
CVE-2018-10692An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. ...
CVE-2018-10691An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log ...
CVE-2018-19999The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local...
CVE-2018-19860Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecif...
CVE-2018-19802aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.
CVE-2018-19801aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.
CVE-2018-19800aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.
CVE-2018-19465Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php ...
CVE-2018-19462admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that...
CVE-2018-19461admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
CVE-2018-19452A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF ...
CVE-2018-19451A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when...
CVE-2018-5264Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free ti...
CVE-2018-20135Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of appl...
CVE-2018-20091An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow...
CVE-2018-20014In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin...
CVE-2018-6185In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undel...
CVE-2018-5798This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager.
CVE-2018-5265Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credential...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now