2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15128 | — | — | 5.2% | May 13, 2019 | An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.... |
| CVE-2018-19037 | — | — | 1.8% | May 13, 2019 | On Virgin Media wireless router 3.0 hub devices, the web interface is vulnerable to denial of service. When POST request... |
| CVE-2018-18558 | — | — | 0.4% | May 13, 2019 | An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of... |
| CVE-2018-16639 | — | — | 0.7% | May 13, 2019 | Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation. |
| CVE-2018-16626 | — | — | 0.7% | May 13, 2019 | index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name. |
| CVE-2018-16625 | — | — | 0.7% | May 13, 2019 | index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. |
| CVE-2018-16624 | — | — | 0.7% | May 13, 2019 | panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page. |
| CVE-2018-16623 | — | — | 0.7% | May 13, 2019 | Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropd... |
| CVE-2018-15530 | — | — | 0.7% | May 13, 2019 | Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom... |
| CVE-2018-14714 | — | — | 27.4% | May 13, 2019 | System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system co... |
| CVE-2018-14713 | — | — | 3.9% | May 13, 2019 | Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary... |
| CVE-2018-14712 | — | — | 4.2% | May 13, 2019 | Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via... |
| CVE-2018-14711 | — | — | 0.6% | May 13, 2019 | Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers... |
| CVE-2018-14710 | — | — | 5.3% | May 13, 2019 | Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript vi... |
| CVE-2018-12304 | — | — | 0.8% | May 13, 2019 | Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript vi... |
| CVE-2018-12303 | — | — | 0.6% | May 13, 2019 | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via direct... |
| CVE-2018-12302 | — | — | 0.8% | May 13, 2019 | Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to stea... |
| CVE-2018-12301 | — | — | 1.4% | May 13, 2019 | Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface... |
| CVE-2018-12300 | — | — | 2.7% | May 13, 2019 | Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in th... |
| CVE-2018-12299 | — | — | 0.6% | May 13, 2019 | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via upload... |
| CVE-2018-12298 | — | — | 1.7% | May 13, 2019 | Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's co... |
| CVE-2018-12297 | — | — | 0.7% | May 13, 2019 | Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via UR... |
| CVE-2018-12296 | — | — | 9.5% | May 13, 2019 | Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attac... |
| CVE-2018-12295 | — | — | 1.1% | May 13, 2019 | SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL com... |
| CVE-2018-20838 | — | — | 1.1% | May 13, 2019 | ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now