2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20849 | — | — | 1.0% | Jun 30, 2019 | Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI. |
| CVE-2018-20848 | — | — | 0.8% | Jun 30, 2019 | Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by... |
| CVE-2018-20814 | — | — | 1.6% | Jun 28, 2019 | An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Pol... |
| CVE-2018-20813 | — | — | 3.1% | Jun 28, 2019 | An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2. |
| CVE-2018-20812 | — | — | 1.1% | Jun 28, 2019 | An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement w... |
| CVE-2018-20811 | — | — | 2.1% | Jun 28, 2019 | A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12. |
| CVE-2018-20810 | — | — | 1.8% | Jun 28, 2019 | Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connec... |
| CVE-2018-20809 | — | — | 2.7% | Jun 28, 2019 | A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and ... |
| CVE-2018-20808 | — | — | 1.6% | Jun 28, 2019 | An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header s... |
| CVE-2018-20807 | — | — | 1.6% | Jun 28, 2019 | An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before ... |
| CVE-2018-17560 | — | — | 0.8% | Jun 28, 2019 | The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS... |
| CVE-2018-17170 | — | — | 2.6% | Jun 28, 2019 | Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remot... |
| CVE-2018-14918 | — | — | 18.0% | Jun 28, 2019 | LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. |
| CVE-2018-14916 | — | — | 17.2% | Jun 28, 2019 | LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion. |
| CVE-2018-14887 | — | — | 1.8% | Jun 28, 2019 | Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterpri... |
| CVE-2018-14886 | — | — | 1.3% | Jun 28, 2019 | The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable... |
| CVE-2018-14885 | — | — | 2.2% | Jun 28, 2019 | Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and ... |
| CVE-2018-14868 | — | — | 0.6% | Jun 28, 2019 | Incorrect access control in the Password Encryption module in Odoo Community 9.0 and Odoo Enterprise 9.0 allows authenti... |
| CVE-2018-14867 | — | — | 1.4% | Jun 28, 2019 | Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 ... |
| CVE-2018-15519 | — | — | 1.2% | Jun 28, 2019 | Various Lexmark devices have a Buffer Overflow (issue 1 of 2). |
| CVE-2018-14919 | — | — | 1.5% | Jun 28, 2019 | LOYTEC LGATE-902 6.3.2 devices allow XSS. |
| CVE-2018-15520 | — | — | 1.2% | Jun 28, 2019 | Various Lexmark devices have a Buffer Overflow (issue 2 of 2). |
| CVE-2018-15555 | — | — | 3.0% | Jun 28, 2019 | On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and pa... |
| CVE-2018-6177 | — | — | 0.9% | Jun 27, 2019 | Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin d... |
| CVE-2018-6176 | — | — | 0.5% | Jun 27, 2019 | Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker wh... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now