2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-6087 | — | — | 3.5% | Dec 4, 2018 | A use-after-free in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary c... |
| CVE-2018-6086 | — | — | 3.3% | Dec 4, 2018 | A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cache in Google Chrome p... |
| CVE-2018-6085 | — | — | 3.6% | Dec 4, 2018 | Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to e... |
| CVE-2018-12319 | — | — | 1.2% | Dec 4, 2018 | Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing ma... |
| CVE-2018-12318 | — | — | 1.1% | Dec 4, 2018 | Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP passwo... |
| CVE-2018-12317 | — | — | 3.4% | Dec 4, 2018 | OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by mo... |
| CVE-2018-12316 | — | — | 3.4% | Dec 4, 2018 | OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying... |
| CVE-2018-12315 | — | — | 0.7% | Dec 4, 2018 | Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without ent... |
| CVE-2018-12314 | — | — | 2.3% | Dec 4, 2018 | Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files b... |
| CVE-2018-12313 | — | — | 4.4% | Dec 4, 2018 | OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authen... |
| CVE-2018-12312 | — | — | 3.4% | Dec 4, 2018 | OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via th... |
| CVE-2018-12311 | — | — | 0.5% | Dec 4, 2018 | Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary J... |
| CVE-2018-12310 | — | — | 0.5% | Dec 4, 2018 | Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the Syste... |
| CVE-2018-12309 | — | — | 1.5% | Dec 4, 2018 | Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations b... |
| CVE-2018-12308 | — | — | 0.6% | Dec 4, 2018 | Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via th... |
| CVE-2018-12307 | — | — | 3.4% | Dec 4, 2018 | OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via th... |
| CVE-2018-12306 | — | — | 1.7% | Dec 4, 2018 | Directory Traversal in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to view arbitrary files by modifying ... |
| CVE-2018-12305 | — | — | 0.7% | Dec 4, 2018 | Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading S... |
| CVE-2018-11348 | — | — | 0.6% | Dec 4, 2018 | Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 w... |
| CVE-2018-11347 | — | — | 1.3% | Dec 4, 2018 | The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection. This flaw allows an... |
| CVE-2018-19854 | — | — | 0.4% | Dec 4, 2018 | An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_us... |
| CVE-2018-16634 | — | — | 0.5% | Dec 4, 2018 | Pluck v4.7.7 allows CSRF via admin.php?action=settings. |
| CVE-2018-16633 | — | — | 0.6% | Dec 4, 2018 | Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. |
| CVE-2018-16631 | — | — | 0.6% | Dec 4, 2018 | Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. |
| CVE-2018-16629 | — | — | 0.6% | Dec 4, 2018 | panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now