2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14696 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthen... |
| CVE-2018-14695 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthen... |
| CVE-2018-6440 | — | — | 2.2% | Dec 3, 2018 | A vulnerability in the proxy service of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remo... |
| CVE-2018-2515 | — | — | — | Dec 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-2815. Reason: This candidate is a duplicate of ... |
| CVE-2018-19836 | — | — | 0.8% | Dec 3, 2018 | In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), an... |
| CVE-2018-19835 | — | — | 0.7% | Dec 3, 2018 | Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter. |
| CVE-2018-19827 | — | — | 2.0% | Dec 3, 2018 | In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that ... |
| CVE-2018-19826 | — | — | 1.2% | Dec 3, 2018 | In inspect.cpp in LibSass 3.5.5, a high memory footprint caused by an endless loop (containing a Sass::Inspect::operator... |
| CVE-2018-19824 | — | — | 0.6% | Dec 3, 2018 | In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malici... |
| CVE-2018-1002009 | — | — | 2.6% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002008 | — | — | 2.6% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002007 | — | — | 2.6% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002006 | — | — | 2.6% | Dec 3, 2018 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact... |
| CVE-2018-1002005 | — | — | 3.1% | Dec 3, 2018 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4... |
| CVE-2018-1002004 | — | — | 2.9% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002003 | — | — | 2.9% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002002 | — | — | 2.9% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002001 | — | — | 2.9% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002000 | — | — | 4.4% | Dec 3, 2018 | There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad... |
| CVE-2018-7116 | — | — | 10.3% | Dec 3, 2018 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote denial of service via... |
| CVE-2018-7115 | — | — | 13.4% | Dec 3, 2018 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in db... |
| CVE-2018-7114 | — | — | 32.8% | Dec 3, 2018 | HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to remote buffer overflow in dbma... |
| CVE-2018-7113 | — | — | 0.7% | Dec 3, 2018 | A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the ... |
| CVE-2018-7112 | — | — | 0.7% | Dec 3, 2018 | The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of pri... |
| CVE-2018-19797 | — | — | 1.8% | Dec 3, 2018 | In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (use... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now