2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13291 | MEDIUM | 4.3 | 1.2% | Apr 1, 2019 | Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 ... |
| CVE-2018-13290 | MEDIUM | 4.3 | 1.3% | Apr 1, 2019 | Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote a... |
| CVE-2018-13289 | MEDIUM | 5.3 | 1.6% | Apr 1, 2019 | Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allow... |
| CVE-2018-13288 | MEDIUM | 5.3 | 1.5% | Apr 1, 2019 | Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.... |
| CVE-2018-13287 | MEDIUM | 6.5 | 1.3% | Apr 1, 2019 | Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows... |
| CVE-2018-13286 | MEDIUM | 6.5 | 1.3% | Apr 1, 2019 | Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 al... |
| CVE-2018-13285 | HIGH | 7.5 | 2.3% | Apr 1, 2019 | Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated... |
| CVE-2018-13284 | HIGH | 7.5 | 2.3% | Apr 1, 2019 | Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authentic... |
| CVE-2018-13283 | HIGH | 8.8 | 1.4% | Apr 1, 2019 | Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 all... |
| CVE-2018-18766 | — | — | 1.2% | Mar 29, 2019 | An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905. |
| CVE-2018-19201 | — | — | 0.8% | Mar 29, 2019 | A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaSc... |
| CVE-2018-15840 | — | — | 1.9% | Mar 29, 2019 | TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets... |
| CVE-2018-20378 | — | — | 2.3% | Mar 29, 2019 | The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow r... |
| CVE-2018-19879 | HIGH | 7.1 | 1.3% | Mar 28, 2019 | An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The ... |
| CVE-2018-16529 | CRITICAL | 9.8 | 1.6% | Mar 28, 2019 | A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be use... |
| CVE-2018-6330 | — | — | 1.6% | Mar 28, 2019 | Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters. |
| CVE-2018-20678 | — | — | 1.4% | Mar 28, 2019 | LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenti... |
| CVE-2018-20144 | — | — | 2.2% | Mar 28, 2019 | GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorre... |
| CVE-2018-19648 | — | — | 1.4% | Mar 27, 2019 | An issue was discovered in ADTRAN PMAA 1.6.2-1, 1.6.3, and 1.6.4. NETCONF Access Management (NACM) allows unprivileged u... |
| CVE-2018-3613 | — | — | 0.4% | Mar 27, 2019 | Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially... |
| CVE-2018-15585 | — | — | 1.5% | Mar 27, 2019 | Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject... |
| CVE-2018-14814 | — | — | 1.5% | Mar 27, 2019 | WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation ... |
| CVE-2018-12545 | HIGH | 7.5 | 5.1% | Mar 27, 2019 | In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client se... |
| CVE-2018-12183 | — | — | 0.5% | Mar 27, 2019 | Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, in... |
| CVE-2018-12182 | — | — | 0.4% | Mar 27, 2019 | Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalati... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now