2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-10854MEDIUM5.4cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in Clou...
CVE-2018-8879CRITICAL9.8Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0....
CVE-2018-9195MEDIUM5.9Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle wit...
CVE-2018-13916HIGH7.8Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve t...
CVE-2018-20687CRITICAL9.8An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway b...
CVE-2018-21031MEDIUM6.5Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server becaus...
CVE-2018-13257MEDIUM6.1The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spo...
CVE-2018-18368HIGH7.8Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerabili...
CVE-2018-12207MEDIUM6.5Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may al...
CVE-2018-21026HIGH7.5A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read inter...
CVE-2018-18819MEDIUM5.3A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0...
CVE-2018-1721HIGH8.8IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat...
CVE-2018-18674MEDIUM6.1GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail conten...
CVE-2018-20853MEDIUM5.3An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plug...
CVE-2018-20320Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11032. Reason: This candidate is a reservation d...
CVE-2018-19167HIGH7.5CloakCoin through 2.2.2.0 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable b...
CVE-2018-19166HIGH7.5peercoin through 0.6.4 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by a...
CVE-2018-19165HIGH7.5neblio through 1.5.1 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an ...
CVE-2018-19164HIGH7.5reddcoin through 2.1.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by...
CVE-2018-19163HIGH7.5stratisX through 2.0.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by...
CVE-2018-19162HIGH7.5Divi through 4.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an at...
CVE-2018-19161HIGH7.5alqo through 4.1 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an atta...
CVE-2018-19160HIGH7.5Diamond through 3.0.1.2 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by ...
CVE-2018-19159HIGH7.5lux through 5.2.2 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an att...
CVE-2018-19157HIGH7.5Phore through 1.3.3.1 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now