2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16490 | — | — | 1.1% | Feb 1, 2019 | A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary propert... |
| CVE-2018-16489 | CRITICAL | 9.8 | 1.8% | Feb 1, 2019 | A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.... |
| CVE-2018-16487 | MEDIUM | 5.6 | 1.6% | Feb 1, 2019 | A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep ... |
| CVE-2018-16486 | — | — | 1.5% | Feb 1, 2019 | A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject prope... |
| CVE-2018-16485 | — | — | 1.3% | Feb 1, 2019 | Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file ... |
| CVE-2018-16484 | — | — | 0.6% | Feb 1, 2019 | A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, du... |
| CVE-2018-16483 | — | — | 1.2% | Feb 1, 2019 | A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the appl... |
| CVE-2018-16482 | HIGH | 7.5 | 1.8% | Feb 1, 2019 | A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to acce... |
| CVE-2018-16481 | — | — | 0.7% | Feb 1, 2019 | A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's br... |
| CVE-2018-16480 | — | — | 0.8% | Feb 1, 2019 | A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due t... |
| CVE-2018-16479 | — | — | 1.7% | Feb 1, 2019 | Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appe... |
| CVE-2018-0722 | — | — | 1.7% | Feb 1, 2019 | Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, ... |
| CVE-2018-18988 | — | — | 2.6% | Feb 1, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report form... |
| CVE-2018-5498 | — | — | 1.2% | Feb 1, 2019 | Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attac... |
| CVE-2018-15617 | MEDIUM | 6.5 | 2.2% | Feb 1, 2019 | A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remo... |
| CVE-2018-15779 | — | — | — | Feb 1, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-5560 | CRITICAL | 10 | 1.6% | Jan 31, 2019 | A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla ... |
| CVE-2018-17928 | — | — | 0.8% | Jan 31, 2019 | The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration f... |
| CVE-2018-6241 | — | — | 0.2% | Jan 31, 2019 | NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the regi... |
| CVE-2018-12548 | — | — | 1.1% | Jan 31, 2019 | In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public ... |
| CVE-2018-19043 | — | — | 10.0% | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)... |
| CVE-2018-19042 | — | — | 10.0% | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di... |
| CVE-2018-19041 | — | — | 2.6% | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the... |
| CVE-2018-19040 | — | — | 12.1% | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para... |
| CVE-2018-18941 | — | — | 2.3% | Jan 31, 2019 | In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discoverin... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now