2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18800 | — | — | 3.2% | May 14, 2019 | The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=... |
| CVE-2018-16138 | — | — | 0.7% | May 13, 2019 | An issue was discovered in the administration page in IPBRICK OS 6.3. There are multiple XSS vulnerabilities. |
| CVE-2018-16137 | — | — | 1.3% | May 13, 2019 | An issue was discovered in the Web Management Console in IPBRICK OS 6.3. There are multiple SQL injections. |
| CVE-2018-16136 | — | — | 0.6% | May 13, 2019 | An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF to... |
| CVE-2018-18912 | — | — | 3.5% | May 13, 2019 | An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs wh... |
| CVE-2018-16139 | — | — | 2.3% | May 13, 2019 | Cross-site scripting (XSS) vulnerability in BIBLIOsoft BIBLIOpac 2008 allows remote attackers to inject arbitrary web sc... |
| CVE-2018-4029 | CRITICAL | 9.8 | 2.9% | May 13, 2019 | An exploitable code execution vulnerability exists in the HTTP request-parsing function of the NT9665X Chipset firmware ... |
| CVE-2018-4028 | HIGH | 7.5 | 1.4% | May 13, 2019 | An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam... |
| CVE-2018-4027 | HIGH | 7.5 | 1.7% | May 13, 2019 | An exploitable denial-of-service vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmwar... |
| CVE-2018-4026 | HIGH | 7.5 | 1.5% | May 13, 2019 | An exploitable denial-of-service vulnerability exists in the XML_GetScreen Wi-Fi command of the NT9665X Chipset firmware... |
| CVE-2018-4025 | HIGH | 7.5 | 1.6% | May 13, 2019 | An exploitable denial-of-service vulnerability exists in the XML_GetRawEncJpg Wi-Fi command of the NT9665X Chipset firmw... |
| CVE-2018-4024 | HIGH | 7.5 | 1.7% | May 13, 2019 | An exploitable denial-of-service vulnerability exists in the thumbnail display functionality of the NT9665X Chipset firm... |
| CVE-2018-4023 | CRITICAL | 9.8 | 2.8% | May 13, 2019 | An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, ... |
| CVE-2018-4018 | CRITICAL | 9.8 | 2.3% | May 13, 2019 | An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware, running on Anker Roav A1 Dashcam ve... |
| CVE-2018-4017 | HIGH | 8.8 | 0.5% | May 13, 2019 | An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.... |
| CVE-2018-4016 | HIGH | 8.8 | 0.7% | May 13, 2019 | An exploitable code execution vulnerability exists in the URL-parsing functionality of the Roav A1 Dashcam running versi... |
| CVE-2018-4014 | CRITICAL | 9.8 | 2.2% | May 13, 2019 | An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SW... |
| CVE-2018-19990 | — | — | 5.3% | May 13, 2019 | In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-8... |
| CVE-2018-19989 | — | — | 5.5% | May 13, 2019 | In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 R... |
| CVE-2018-19988 | — | — | 7.4% | May 13, 2019 | In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilitie... |
| CVE-2018-19987 | — | — | 12.9% | May 13, 2019 | D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.... |
| CVE-2018-19986 | — | — | 41.6% | May 13, 2019 | In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DI... |
| CVE-2018-19048 | — | — | 1.5% | May 13, 2019 | Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element. |
| CVE-2018-18872 | — | — | 0.7% | May 13, 2019 | The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin... |
| CVE-2018-18524 | — | — | 1.9% | May 13, 2019 | Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inj... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now