2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13332 | — | — | 2.3% | Nov 27, 2018 | Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to ar... |
| CVE-2018-13331 | — | — | 1.1% | Nov 27, 2018 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when view... |
| CVE-2018-13330 | — | — | 8.1% | Nov 27, 2018 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands d... |
| CVE-2018-18982 | — | — | 60.8% | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b... |
| CVE-2018-17936 | — | — | 15.3% | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co... |
| CVE-2018-17934 | — | — | 19.7% | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be res... |
| CVE-2018-16130 | — | — | 24.0% | Nov 27, 2018 | System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary sys... |
| CVE-2018-14893 | — | — | 3.4% | Nov 27, 2018 | A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute syste... |
| CVE-2018-14892 | — | — | 0.9% | Nov 27, 2018 | Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow atta... |
| CVE-2018-13337 | — | — | 1.2% | Nov 27, 2018 | Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session co... |
| CVE-2018-13334 | — | — | 1.1% | Nov 27, 2018 | Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "opt... |
| CVE-2018-13329 | — | — | 1.1% | Nov 27, 2018 | Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "l... |
| CVE-2018-13316 | — | — | 3.2% | Nov 27, 2018 | System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands vi... |
| CVE-2018-13314 | — | — | 3.2% | Nov 27, 2018 | System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands vi... |
| CVE-2018-13307 | — | — | 3.2% | Nov 27, 2018 | System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via th... |
| CVE-2018-13306 | — | — | 3.2% | Nov 27, 2018 | System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via t... |
| CVE-2018-13023 | — | — | 24.0% | Nov 27, 2018 | System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute ... |
| CVE-2018-13022 | — | — | 0.7% | Nov 27, 2018 | Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute... |
| CVE-2018-10142 | — | — | 2.2% | Nov 27, 2018 | The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operat... |
| CVE-2018-17256 | — | — | 0.7% | Nov 27, 2018 | Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary... |
| CVE-2018-6266 | — | — | 0.3% | Nov 27, 2018 | NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtai... |
| CVE-2018-6265 | — | — | 0.3% | Nov 27, 2018 | NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Wind... |
| CVE-2018-6263 | — | — | 0.3% | Nov 27, 2018 | NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows in which an attacker who has... |
| CVE-2018-12241 | — | — | 1.0% | Nov 27, 2018 | The Symantec Security Analytics (SA) 7.x prior to 7.3.4 Web UI is susceptible to a reflected cross-site scripting (XSS) ... |
| CVE-2018-6983 | — | — | 0.5% | Nov 27, 2018 | VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now