2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19796 | — | — | 1.6% | Dec 3, 2018 | An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via ... |
| CVE-2018-19795 | — | — | 0.4% | Dec 3, 2018 | ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full a... |
| CVE-2018-19794 | — | — | 1.1% | Dec 3, 2018 | Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to... |
| CVE-2018-19793 | — | — | 2.4% | Dec 3, 2018 | jiacrontab 1.4.5 allows remote attackers to execute arbitrary commands via the crontab/task/edit?addr=localhost%3a20001 ... |
| CVE-2018-19792 | — | — | 0.4% | Dec 3, 2018 | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 allows local users to cause a denial of service (buffer overflow)... |
| CVE-2018-19791 | — | — | 1.2% | Dec 3, 2018 | The server in LiteSpeed OpenLiteSpeed before 1.5.0 RC6 does not correctly handle requests for byte sequences, allowing a... |
| CVE-2018-19788 | — | — | 11.5% | Dec 3, 2018 | A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully exec... |
| CVE-2018-19785 | — | — | 0.9% | Dec 1, 2018 | PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php. |
| CVE-2018-19784 | — | — | 1.1% | Dec 1, 2018 | The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, whic... |
| CVE-2018-15716 | — | — | 18.5% | Nov 30, 2018 | NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques... |
| CVE-2018-15715 | — | — | 3.5% | Nov 30, 2018 | Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0... |
| CVE-2018-7831 | — | — | 0.6% | Nov 30, 2018 | An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded we... |
| CVE-2018-7830 | — | — | 2.4% | Nov 30, 2018 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedd... |
| CVE-2018-7811 | — | — | 3.5% | Nov 30, 2018 | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLC... |
| CVE-2018-7810 | — | — | 0.9% | Nov 30, 2018 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embe... |
| CVE-2018-7809 | — | — | 2.5% | Nov 30, 2018 | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLC... |
| CVE-2018-7807 | — | — | 1.3% | Nov 30, 2018 | Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the serve... |
| CVE-2018-7806 | — | — | 1.3% | Nov 30, 2018 | Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, ma... |
| CVE-2018-16477 | — | — | 1.3% | Nov 30, 2018 | A bypass vulnerability in Active Storage >= 5.2.0 for Google Cloud Storage and Disk services allow an attacker to modify... |
| CVE-2018-16476 | — | — | 2.6% | Nov 30, 2018 | A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can c... |
| CVE-2018-19290 | — | — | 4.0% | Nov 30, 2018 | In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command... |
| CVE-2018-18987 | — | — | 3.2% | Nov 30, 2018 | VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without... |
| CVE-2018-18983 | — | — | 2.9% | Nov 30, 2018 | VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) in... |
| CVE-2018-18860 | — | — | 1.2% | Nov 30, 2018 | A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-... |
| CVE-2018-15835 | — | — | 2.0% | Nov 30, 2018 | Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now