2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20555 | — | — | 10.4% | Mar 21, 2019 | The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_to... |
| CVE-2018-20526 | — | — | 73.7% | Mar 21, 2019 | Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. |
| CVE-2018-20525 | CRITICAL | 9.1 | 21.6% | Mar 21, 2019 | Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php. |
| CVE-2018-20340 | — | — | 0.5% | Mar 21, 2019 | Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer ... |
| CVE-2018-20323 | — | — | 55.1% | Mar 21, 2019 | www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitra... |
| CVE-2018-20221 | — | — | 10.5% | Mar 21, 2019 | Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ... |
| CVE-2018-20220 | — | — | 15.4% | Mar 21, 2019 | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authen... |
| CVE-2018-20219 | — | — | 14.6% | Mar 21, 2019 | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the de... |
| CVE-2018-20218 | — | — | 10.7% | Mar 21, 2019 | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input direct... |
| CVE-2018-20212 | — | — | 1.6% | Mar 21, 2019 | bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter. |
| CVE-2018-20162 | — | — | 4.2% | Mar 21, 2019 | Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' ... |
| CVE-2018-20141 | — | — | 1.6% | Mar 21, 2019 | AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--access... |
| CVE-2018-20140 | — | — | 1.6% | Mar 21, 2019 | Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters. |
| CVE-2018-20121 | — | — | 1.6% | Mar 21, 2019 | Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter. |
| CVE-2018-19985 | — | — | 1.0% | Mar 21, 2019 | The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB d... |
| CVE-2018-19934 | — | — | 5.5% | Mar 21, 2019 | SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL ... |
| CVE-2018-1992 | MEDIUM | 6.4 | 0.4% | Mar 21, 2019 | The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial... |
| CVE-2018-19917 | — | — | 1.6% | Mar 21, 2019 | Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities. |
| CVE-2018-19872 | — | — | 1.4% | Mar 21, 2019 | An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp. |
| CVE-2018-19783 | — | — | 3.6% | Mar 21, 2019 | Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel. |
| CVE-2018-19694 | — | — | 1.6% | Mar 21, 2019 | HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form. |
| CVE-2018-19525 | — | — | 0.9% | Mar 21, 2019 | An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF ... |
| CVE-2018-19524 | — | — | 50.5% | Mar 21, 2019 | An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTB... |
| CVE-2018-19515 | — | — | 2.9% | Mar 21, 2019 | In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, ... |
| CVE-2018-19514 | — | — | 4.9% | Mar 21, 2019 | In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now