2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14865 | — | — | 1.5% | Jul 3, 2019 | Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not u... |
| CVE-2018-14864 | — | — | 1.2% | Jul 3, 2019 | Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through... |
| CVE-2018-14863 | — | — | 1.0% | Jul 3, 2019 | Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 al... |
| CVE-2018-14862 | — | — | 0.8% | Jul 3, 2019 | Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and e... |
| CVE-2018-14861 | — | — | 1.0% | Jul 3, 2019 | Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated user... |
| CVE-2018-14866 | — | — | 0.8% | Jul 3, 2019 | Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and... |
| CVE-2018-12715 | MEDIUM | 6.1 | 0.9% | Jul 3, 2019 | DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged. |
| CVE-2018-18326 | HIGH | 7.5 | 53.6% | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expect... |
| CVE-2018-18325 | HIGH | 7.5 | 74.0% | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue ex... |
| CVE-2018-15812 | HIGH | 7.5 | 46.5% | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect... |
| CVE-2018-15811 | HIGH | 7.5 | 74.0% | Jul 3, 2019 | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. |
| CVE-2018-12250 | — | — | 1.6% | Jul 3, 2019 | An issue was discovered in Elite CMS Pro 2.01. In /admin/add_sidebar.php, the ?page= parameter is vulnerable to SQL inje... |
| CVE-2018-11686 | — | — | 49.8% | Jul 3, 2019 | The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c... |
| CVE-2018-10986 | — | — | 0.5% | Jul 3, 2019 | OX Guard 2.8.0 has CSRF. |
| CVE-2018-11425 | — | — | 1.5% | Jul 3, 2019 | Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a differen... |
| CVE-2018-11424 | — | — | 1.4% | Jul 3, 2019 | There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a... |
| CVE-2018-11423 | — | — | 1.4% | Jul 3, 2019 | There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, diff... |
| CVE-2018-11422 | — | — | 1.0% | Jul 3, 2019 | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does no... |
| CVE-2018-11421 | — | — | 0.9% | Jul 3, 2019 | Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not p... |
| CVE-2018-11420 | — | — | 1.5% | Jul 3, 2019 | There is Memory corruption in the web interface of Moxa OnCell G3100-HSPA Series version 1.5 Build 17042015 and prio,r a... |
| CVE-2018-11317 | — | — | 0.9% | Jul 3, 2019 | Subrion CMS before 4.1.4 has XSS. |
| CVE-2018-11227 | — | — | 4.8% | Jul 3, 2019 | Monstra CMS 3.0.4 and earlier has XSS via index.php. |
| CVE-2018-11215 | — | — | 2.4% | Jul 3, 2019 | Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified at... |
| CVE-2018-11427 | — | — | 0.6% | Jul 3, 2019 | CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, w... |
| CVE-2018-11426 | — | — | 1.8% | Jul 3, 2019 | A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and p... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now