2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19766 | — | — | 1.1% | Dec 17, 2018 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "GroupRessourceAdmin.jsp" ha... |
| CVE-2018-19765 | — | — | 1.1% | Dec 17, 2018 | Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPresentSpace.jsp... |
| CVE-2018-19649 | — | — | 1.1% | Dec 17, 2018 | XSS exists in InfoVista VistaPortal SE Version 5.1 (build 51029). VPortal/mgtconsole/RolePermissions.jsp has reflected X... |
| CVE-2018-19295 | — | — | 0.5% | Dec 17, 2018 | Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks. |
| CVE-2018-18250 | — | — | 1.0% | Dec 17, 2018 | Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as... |
| CVE-2018-18249 | — | — | 1.5% | Dec 17, 2018 | Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the... |
| CVE-2018-18248 | — | — | 0.7% | Dec 17, 2018 | Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string,... |
| CVE-2018-18247 | — | — | 0.6% | Dec 17, 2018 | Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter. |
| CVE-2018-18246 | — | — | 0.5% | Dec 17, 2018 | Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module... |
| CVE-2018-18245 | — | — | 2.6% | Dec 17, 2018 | Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered... |
| CVE-2018-20173 | — | — | 24.5% | Dec 17, 2018 | Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API. |
| CVE-2018-20170 | — | — | 1.1% | Dec 17, 2018 | OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster respon... |
| CVE-2018-20168 | — | — | 0.3% | Dec 17, 2018 | Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which al... |
| CVE-2018-20167 | — | — | 2.7% | Dec 17, 2018 | Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat ... |
| CVE-2018-20161 | — | — | 0.7% | Dec 15, 2018 | A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable camera... |
| CVE-2018-20159 | — | — | 9.9% | Dec 15, 2018 | i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allow... |
| CVE-2018-20157 | — | — | 1.7% | Dec 15, 2018 | The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zi... |
| CVE-2018-20156 | — | — | 1.5% | Dec 14, 2018 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to exec... |
| CVE-2018-20155 | — | — | 0.8% | Dec 14, 2018 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intende... |
| CVE-2018-20154 | — | — | 1.0% | Dec 14, 2018 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e... |
| CVE-2018-20153 | — | — | 2.5% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privil... |
| CVE-2018-20152 | — | — | 4.2% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted inp... |
| CVE-2018-20151 | — | — | 6.7% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler ... |
| CVE-2018-20150 | — | — | 5.1% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. |
| CVE-2018-20149 | — | — | 3.4% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now