2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18762SaltOS 3.1 r8126 contains a database download vulnerability.
CVE-2018-18473A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmw...
CVE-2018-18466An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the appl...
CVE-2018-18435KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any...
CVE-2018-17997LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
CVE-2018-17996LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_...
CVE-2018-17167PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name...
CVE-2018-16789libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a cra...
CVE-2018-16563A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firm...
CVE-2018-16519COYO 9.0.8, 10.0.11 and 12.0.4 has cross-site scripting (XSS) via URLs used by "iFrame" widgets.
CVE-2018-15906SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import...
CVE-2018-15818An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web...
CVE-2018-15532SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed...
CVE-2018-15508Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service v...
CVE-2018-15498YSoft SafeQ Server 6 allows a replay attack.
CVE-2018-14745Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 al...
CVE-2018-14724In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ...
CVE-2018-14575Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CS...
CVE-2018-14486DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
CVE-2018-13104OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)
CVE-2018-13103OX App Suite 7.8.4 and earlier allows SSRF.
CVE-2018-12638An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device n...
CVE-2018-12572Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain...
CVE-2018-12023An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enab...
CVE-2018-11789When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any fil...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now