2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-20555The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_to...
CVE-2018-20526Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
CVE-2018-20525CRITICAL9.1Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
CVE-2018-20340Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer ...
CVE-2018-20323www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitra...
CVE-2018-20221Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ...
CVE-2018-20220An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authen...
CVE-2018-20219An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the de...
CVE-2018-20218An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input direct...
CVE-2018-20212bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
CVE-2018-20162Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' ...
CVE-2018-20141AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--access...
CVE-2018-20140Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.
CVE-2018-20121Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter.
CVE-2018-19985The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB d...
CVE-2018-19934SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL ...
CVE-2018-1992MEDIUM6.4The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial...
CVE-2018-19917Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
CVE-2018-19872An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
CVE-2018-19783Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel.
CVE-2018-19694HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.
CVE-2018-19525An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF ...
CVE-2018-19524An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTB...
CVE-2018-19515In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, ...
CVE-2018-19514In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now