2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16628 | — | — | 0.6% | Dec 4, 2018 | panel/login in Kirby v2.5.12 allows XSS via a blog name. |
| CVE-2018-17159 | — | — | 4.2% | Dec 4, 2018 | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS r... |
| CVE-2018-17158 | — | — | 4.4% | Dec 4, 2018 | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client... |
| CVE-2018-17157 | — | — | 24.2% | Dec 4, 2018 | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause me... |
| CVE-2018-16478 | — | — | 1.3% | Dec 4, 2018 | A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root. |
| CVE-2018-19853 | — | — | 0.9% | Dec 4, 2018 | An issue was discovered in hitshop through 2014-07-15. There is an elevation-of-privilege vulnerability (that allows con... |
| CVE-2018-19849 | — | — | 0.5% | Dec 4, 2018 | An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter. |
| CVE-2018-19843 | — | — | 1.0% | Dec 4, 2018 | opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read... |
| CVE-2018-19842 | — | — | 1.0% | Dec 4, 2018 | getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based b... |
| CVE-2018-19840 | — | — | 2.3% | Dec 4, 2018 | The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial... |
| CVE-2018-19839 | — | — | 2.2% | Dec 4, 2018 | In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service r... |
| CVE-2018-19838 | — | — | 1.9% | Dec 4, 2018 | In LibSass prior to 3.5.5, functions inside ast.cpp for IMPLEMENT_AST_OPERATORS expansion allow attackers to cause a den... |
| CVE-2018-19837 | — | — | 1.8% | Dec 4, 2018 | In LibSass prior to 3.5.5, Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp allows attackers to cause a ... |
| CVE-2018-14709 | — | — | 1.9% | Dec 3, 2018 | Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass auth... |
| CVE-2018-14708 | — | — | 1.3% | Dec 3, 2018 | An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers t... |
| CVE-2018-14707 | — | — | 27.8% | Dec 3, 2018 | Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated a... |
| CVE-2018-14706 | — | — | 17.1% | Dec 3, 2018 | System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows u... |
| CVE-2018-14704 | — | — | 0.7% | Dec 3, 2018 | Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute ... |
| CVE-2018-14703 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unau... |
| CVE-2018-14702 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unaut... |
| CVE-2018-14701 | — | — | 20.0% | Dec 3, 2018 | System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unau... |
| CVE-2018-14700 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauth... |
| CVE-2018-14699 | — | — | 29.4% | Dec 3, 2018 | System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unau... |
| CVE-2018-14698 | — | — | 0.7% | Dec 3, 2018 | Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attacker... |
| CVE-2018-14697 | — | — | 0.7% | Dec 3, 2018 | Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attacker... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now