2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18976An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker ...
CVE-2018-18975An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communicat...
CVE-2018-4073An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie...
CVE-2018-4072An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sie...
CVE-2018-4071An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si...
CVE-2018-4070An exploitable Information Disclosure vulnerability exists in the ACEManager EmbeddedAceGet_Task.cgi functionality of Si...
CVE-2018-4067An exploitable information disclosure vulnerability exists in the ACEManager template_load.cgi functionality of Sierra W...
CVE-2018-4066An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLin...
CVE-2018-4065An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wirel...
CVE-2018-4062A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activ...
CVE-2018-13983ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/i...
CVE-2018-4069An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink...
CVE-2018-4068An exploitable information disclosure vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES...
CVE-2018-4061An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless A...
CVE-2018-17202Certain input files could make the code to enter into an infinite loop when Apache Sanselan 0.97-incubator was used to p...
CVE-2018-17201Certain input files could make the code hang when Apache Sanselan 0.97-incubator was used to parse them, which could be ...
CVE-2018-20824The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScri...
CVE-2018-20580The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co...
CVE-2018-16961An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the f...
CVE-2018-16960An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal...
CVE-2018-16718An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted ...
CVE-2018-16717A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.
CVE-2018-16716A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, whic...
CVE-2018-10383Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
CVE-2018-12404A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content....

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now