2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1328 | — | — | 6.0% | Apr 23, 2019 | Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph". |
| CVE-2018-1317 | — | — | 4.7% | Apr 23, 2019 | In Apache Zeppelin prior to 0.8.0 the cron scheduler was enabled by default and could allow users to run paragraphs as o... |
| CVE-2018-20820 | — | — | 1.0% | Apr 23, 2019 | read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime cras... |
| CVE-2018-20819 | — | — | 1.0% | Apr 23, 2019 | io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of servi... |
| CVE-2018-17169 | — | — | 1.5% | Apr 23, 2019 | An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to rea... |
| CVE-2018-20818 | — | — | 1.5% | Apr 22, 2019 | A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It ... |
| CVE-2018-20817 | — | — | 3.6% | Apr 19, 2019 | SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when... |
| CVE-2018-20200 | — | — | 2.5% | Apr 18, 2019 | CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by ... |
| CVE-2018-17289 | — | — | 1.5% | Apr 18, 2019 | An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 a... |
| CVE-2018-17288 | — | — | 0.6% | Apr 18, 2019 | Kofax Front Office Server version 4.1.1.11.0.5212 (both Thin Client and Administration Console) suffers from multiple au... |
| CVE-2018-17287 | — | — | 0.4% | Apr 18, 2019 | In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in t... |
| CVE-2018-17168 | — | — | 0.5% | Apr 18, 2019 | PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration pag... |
| CVE-2018-20028 | — | — | 0.9% | Apr 17, 2019 | Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control. |
| CVE-2018-18094 | — | — | 0.3% | Apr 17, 2019 | Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to p... |
| CVE-2018-13378 | — | — | 1.3% | Apr 17, 2019 | An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext... |
| CVE-2018-10959 | — | — | 1.6% | Apr 17, 2019 | Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by ... |
| CVE-2018-16559 | — | — | 2.0% | Apr 17, 2019 | A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All v... |
| CVE-2018-16558 | — | — | 2.0% | Apr 17, 2019 | A vulnerability has been identified in SIMATIC S7-1500 CPU (All versions >= V2.0 and < V2.5), SIMATIC S7-1500 CPU (All v... |
| CVE-2018-13810 | — | — | 0.5% | Apr 17, 2019 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web ... |
| CVE-2018-13809 | — | — | 0.8% | Apr 17, 2019 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated web server of the ... |
| CVE-2018-13808 | — | — | 1.8% | Apr 17, 2019 | A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). An attacker with network access t... |
| CVE-2018-4857 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-16584 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-16582 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2018-16583 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now