2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-13291MEDIUM4.3Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 ...
CVE-2018-13290MEDIUM4.3Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote a...
CVE-2018-13289MEDIUM5.3Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allow...
CVE-2018-13288MEDIUM5.3Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1....
CVE-2018-13287MEDIUM6.5Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows...
CVE-2018-13286MEDIUM6.5Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 al...
CVE-2018-13285HIGH7.5Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated...
CVE-2018-13284HIGH7.5Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authentic...
CVE-2018-13283HIGH8.8Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 all...
CVE-2018-18766An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905.
CVE-2018-19201A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaSc...
CVE-2018-15840TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets...
CVE-2018-20378The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow r...
CVE-2018-19879HIGH7.1An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The ...
CVE-2018-16529CRITICAL9.8A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be use...
CVE-2018-6330Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.
CVE-2018-20678LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenti...
CVE-2018-20144GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorre...
CVE-2018-19648An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged u...
CVE-2018-3613Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially...
CVE-2018-15585Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject...
CVE-2018-14814WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation ...
CVE-2018-12545HIGH7.5In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client se...
CVE-2018-12183Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, in...
CVE-2018-12182Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalati...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now