2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20851Helpy before 2.2.0 allows agents to edit admins.
CVE-2018-17147Nagios XI before 5.5.4 has XSS in the auto login admin management page.
CVE-2018-14496Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow...
CVE-2018-14495Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device...
CVE-2018-14494Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarificatio...
CVE-2018-14550HIGH8.8An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow i...
CVE-2018-12628An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privil...
CVE-2018-12627An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authori...
CVE-2018-12626An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.
CVE-2018-12625An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
CVE-2018-12623An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.
CVE-2018-12622An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.
CVE-2018-11307CRITICAL9.8An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a ga...
CVE-2018-15738An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulner...
CVE-2018-14833Intuit Lacerte 2017 has Incorrect Access Control.
CVE-2018-11563MEDIUM4.6An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be...
CVE-2018-16386An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be ac...
CVE-2018-14733The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS...
CVE-2018-14529Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashe...
CVE-2018-14528Invoxia NVX220 devices allow TELNET access as admin with a default password.
CVE-2018-12621An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
CVE-2018-14027Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
CVE-2018-20850Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of ...
CVE-2018-14860Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlie...
CVE-2018-14859Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now