2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18976——An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker ...
CVE-2018-18975——An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communicat...
CVE-2018-4073——An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie...
CVE-2018-4072——An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie...
CVE-2018-4071——An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si...
CVE-2018-4070——An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si...
CVE-2018-4067——An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra W...
CVE-2018-4066——An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLin...
CVE-2018-4065——An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wirel...
CVE-2018-4062——A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activ...
CVE-2018-13983——ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/i...
CVE-2018-4069——An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink...
CVE-2018-4068——An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES...
CVE-2018-4061——An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless A...
CVE-2018-17202——Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to p...
CVE-2018-17201——Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be ...
CVE-2018-20824——The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScri...
CVE-2018-20580——The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co...
CVE-2018-16961——An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the f...
CVE-2018-16960——An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal...
CVE-2018-16718——An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted ...
CVE-2018-16717——A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.
CVE-2018-16716——A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, whic...
CVE-2018-10383——Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
CVE-2018-12404——A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content....

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now