2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20851——Helpy before 2.2.0 allows agents to edit admins.
CVE-2018-17147——Nagios XI before 5.5.4 has XSS in the auto login admin management page.
CVE-2018-14496——Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow...
CVE-2018-14495——Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device...
CVE-2018-14494——Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarificatio...
CVE-2018-14550HIGH8.8An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow i...
CVE-2018-12628——An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privil...
CVE-2018-12627——An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authori...
CVE-2018-12626——An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.
CVE-2018-12625——An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
CVE-2018-12623——An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.
CVE-2018-12622——An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.
CVE-2018-11307CRITICAL9.8An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a ga...
CVE-2018-15738——An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulner...
CVE-2018-14833——Intuit Lacerte 2017 has Incorrect Access Control.
CVE-2018-11563MEDIUM4.6An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be...
CVE-2018-16386——An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be ac...
CVE-2018-14733——The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS...
CVE-2018-14529——Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashe...
CVE-2018-14528——Invoxia NVX220 devices allow TELNET access as admin with a default password.
CVE-2018-12621——An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
CVE-2018-14027——Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
CVE-2018-20850——Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of ...
CVE-2018-14860——Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlie...
CVE-2018-14859——Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now