2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-13332Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to ar...
CVE-2018-13331Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when view...
CVE-2018-13330System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands d...
CVE-2018-18982NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b...
CVE-2018-17936NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co...
CVE-2018-17934NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be res...
CVE-2018-16130System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary sys...
CVE-2018-14893A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute syste...
CVE-2018-14892Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow atta...
CVE-2018-13337Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session co...
CVE-2018-13334Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "opt...
CVE-2018-13329Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "l...
CVE-2018-13316System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands vi...
CVE-2018-13314System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands vi...
CVE-2018-13307System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via th...
CVE-2018-13306System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via t...
CVE-2018-13023System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute ...
CVE-2018-13022Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute...
CVE-2018-10142The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operat...
CVE-2018-17256Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary...
CVE-2018-6266NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtai...
CVE-2018-6265NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Wind...
CVE-2018-6263NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows in which an attacker who has...
CVE-2018-12241The Symantec Security Analytics (SA) 7.x prior to 7.3.4 Web UI is susceptible to a reflected cross-site scripting (XSS) ...
CVE-2018-6983VMware Workstation (15.x before 15.0.2 and 14.x before 14.1.5) and Fusion (11.x before 11.0.2 and 10.x before 10.1.5) co...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now