2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19249 | — | — | 1.4% | Jan 3, 2019 | The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens ... |
| CVE-2018-18997 | — | — | 0.9% | Jan 3, 2019 | Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker usi... |
| CVE-2018-18995 | — | — | 2.6% | Jan 3, 2019 | Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configu... |
| CVE-2018-19601 | — | — | 1.4% | Jan 3, 2019 | Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload. |
| CVE-2018-19600 | — | — | 0.7% | Jan 3, 2019 | Rhymix CMS 1.9.8.1 allows XSS via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload. |
| CVE-2018-18244 | — | — | 0.8% | Jan 3, 2019 | Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote... |
| CVE-2018-18005 | — | — | 0.8% | Jan 3, 2019 | Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows re... |
| CVE-2018-18004 | — | — | 0.9% | Jan 3, 2019 | Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X0... |
| CVE-2018-20664 | — | — | 8.1% | Jan 3, 2019 | Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. |
| CVE-2018-20663 | — | — | 0.7% | Jan 3, 2019 | The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "... |
| CVE-2018-20512 | — | — | 1.8% | Jan 3, 2019 | EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and ti... |
| CVE-2018-19998 | — | — | 2.2% | Jan 3, 2019 | SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbi... |
| CVE-2018-19995 | — | — | 1.1% | Jan 3, 2019 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrar... |
| CVE-2018-19994 | — | — | 2.0% | Jan 3, 2019 | An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated use... |
| CVE-2018-19993 | — | — | 1.4% | Jan 3, 2019 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web s... |
| CVE-2018-19992 | — | — | 1.1% | Jan 3, 2019 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrar... |
| CVE-2018-19862 | — | — | 12.6% | Jan 3, 2019 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re... |
| CVE-2018-19861 | — | — | 12.6% | Jan 3, 2019 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re... |
| CVE-2018-19523 | — | — | 0.3% | Jan 3, 2019 | DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user ... |
| CVE-2018-19505 | — | — | 1.6% | Jan 3, 2019 | Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, w... |
| CVE-2018-19415 | — | — | 1.5% | Jan 3, 2019 | Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via ... |
| CVE-2018-19414 | — | — | 2.2% | Jan 3, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to inject arbitrary web s... |
| CVE-2018-14481 | — | — | 1.1% | Jan 3, 2019 | Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280. |
| CVE-2018-17161 | — | — | 3.5% | Jan 3, 2019 | In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validat... |
| CVE-2018-16870 | — | — | 1.6% | Jan 3, 2019 | It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now