2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18976 | — | — | 1.1% | May 6, 2019 | An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker ... |
| CVE-2018-18975 | — | — | 1.0% | May 6, 2019 | An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communicat... |
| CVE-2018-4073 | — | — | 25.4% | May 6, 2019 | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie... |
| CVE-2018-4072 | — | — | 26.6% | May 6, 2019 | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie... |
| CVE-2018-4071 | — | — | 18.6% | May 6, 2019 | An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si... |
| CVE-2018-4070 | — | — | 18.3% | May 6, 2019 | An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si... |
| CVE-2018-4067 | — | — | 4.1% | May 6, 2019 | An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra W... |
| CVE-2018-4066 | — | — | 2.2% | May 6, 2019 | An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLin... |
| CVE-2018-4065 | — | — | 5.2% | May 6, 2019 | An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wirel... |
| CVE-2018-4062 | — | — | 5.3% | May 6, 2019 | A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activ... |
| CVE-2018-13983 | — | — | 1.5% | May 6, 2019 | ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/i... |
| CVE-2018-4069 | — | — | 4.0% | May 6, 2019 | An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink... |
| CVE-2018-4068 | — | — | 11.4% | May 6, 2019 | An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES... |
| CVE-2018-4061 | — | — | 19.5% | May 6, 2019 | An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless A... |
| CVE-2018-17202 | — | — | 1.9% | May 6, 2019 | Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to p... |
| CVE-2018-17201 | — | — | 1.9% | May 6, 2019 | Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be ... |
| CVE-2018-20824 | — | — | 37.6% | May 3, 2019 | The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScri... |
| CVE-2018-20580 | — | — | 9.8% | May 3, 2019 | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co... |
| CVE-2018-16961 | — | — | 2.5% | May 2, 2019 | An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the f... |
| CVE-2018-16960 | — | — | 0.8% | May 2, 2019 | An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal... |
| CVE-2018-16718 | — | — | 0.8% | May 2, 2019 | An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted ... |
| CVE-2018-16717 | — | — | 1.6% | May 2, 2019 | A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox. |
| CVE-2018-16716 | — | — | 8.6% | May 2, 2019 | A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, whic... |
| CVE-2018-10383 | — | — | 1.9% | May 2, 2019 | Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page. |
| CVE-2018-12404 | — | — | 44.4% | May 2, 2019 | A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content.... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now