2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19513 | — | — | 2.1% | Mar 21, 2019 | In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql... |
| CVE-2018-19512 | — | — | 7.4% | Mar 21, 2019 | In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary ... |
| CVE-2018-19511 | — | — | 0.7% | Mar 21, 2019 | wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change... |
| CVE-2018-19510 | — | — | 20.0% | Mar 21, 2019 | subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header. |
| CVE-2018-19509 | — | — | 1.1% | Mar 21, 2019 | wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with prope... |
| CVE-2018-19498 | — | — | 1.6% | Mar 21, 2019 | The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Server has XSS. |
| CVE-2018-19488 | — | — | 4.1% | Mar 21, 2019 | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() functi... |
| CVE-2018-19487 | — | — | 4.9% | Mar 21, 2019 | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profi... |
| CVE-2018-19365 | CRITICAL | 9.1 | 22.0% | Mar 21, 2019 | The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via ... |
| CVE-2018-19276 | CRITICAL | 9.8 | 98.8% | Mar 21, 2019 | OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use... |
| CVE-2018-19191 | — | — | 39.6% | Mar 21, 2019 | Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the... |
| CVE-2018-19158 | HIGH | 7.5 | 2.6% | Mar 21, 2019 | ColossusCoinXT through 1.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitabl... |
| CVE-2018-18898 | HIGH | 7.5 | 2.4% | Mar 21, 2019 | The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote atta... |
| CVE-2018-18882 | — | — | 0.7% | Mar 21, 2019 | A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data... |
| CVE-2018-18881 | — | — | 1.6% | Mar 21, 2019 | A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisiti... |
| CVE-2018-18862 | — | — | 2.9% | Mar 21, 2019 | BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demons... |
| CVE-2018-18849 | — | — | 0.6% | Mar 21, 2019 | In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value. |
| CVE-2018-18845 | — | — | 1.4% | Mar 21, 2019 | internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, ve... |
| CVE-2018-18798 | — | — | 3.2% | Mar 21, 2019 | Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.ph... |
| CVE-2018-18762 | — | — | 6.2% | Mar 21, 2019 | SaltOS 3.1 r8126 contains a database download vulnerability. |
| CVE-2018-18473 | — | — | 5.6% | Mar 21, 2019 | A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmw... |
| CVE-2018-18466 | — | — | 0.3% | Mar 21, 2019 | An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the appl... |
| CVE-2018-18435 | — | — | 1.4% | Mar 21, 2019 | KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any... |
| CVE-2018-1836 | MEDIUM | 5.4 | 1.0% | Mar 21, 2019 | IBM WebSphere MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.1.0.0, and 9.1.0.1 console is vulnerable to cross-site scripting. This vu... |
| CVE-2018-17997 | — | — | 3.6% | Mar 21, 2019 | LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now