2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13315 | — | — | 1.6% | Nov 26, 2018 | Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin use... |
| CVE-2018-13312 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScrip... |
| CVE-2018-13311 | — | — | 2.5% | Nov 26, 2018 | System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via t... |
| CVE-2018-13310 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript ... |
| CVE-2018-13309 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript ... |
| CVE-2018-13308 | — | — | 0.7% | Nov 26, 2018 | Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScrip... |
| CVE-2018-19568 | — | — | 0.9% | Nov 26, 2018 | A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malici... |
| CVE-2018-19567 | — | — | 0.9% | Nov 26, 2018 | A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious f... |
| CVE-2018-19566 | — | — | 1.1% | Nov 26, 2018 | A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious file... |
| CVE-2018-19565 | — | — | 1.1% | Nov 26, 2018 | A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files... |
| CVE-2018-11077 | — | — | 1.0% | Nov 26, 2018 | 'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and... |
| CVE-2018-11076 | — | — | 0.8% | Nov 26, 2018 | Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appl... |
| CVE-2018-11067 | — | — | 1.8% | Nov 26, 2018 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1... |
| CVE-2018-11066 | — | — | 9.9% | Nov 26, 2018 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1... |
| CVE-2018-19564 | — | — | 0.9% | Nov 26, 2018 | Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_c... |
| CVE-2018-19562 | — | — | 2.2% | Nov 26, 2018 | An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code v... |
| CVE-2018-19561 | — | — | 0.4% | Nov 26, 2018 | sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account. |
| CVE-2018-19560 | — | — | 0.7% | Nov 26, 2018 | BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account. |
| CVE-2018-19559 | — | — | 1.0% | Nov 26, 2018 | CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter. |
| CVE-2018-19558 | — | — | 1.1% | Nov 26, 2018 | An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because ... |
| CVE-2018-19557 | — | — | 1.5% | Nov 26, 2018 | An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/... |
| CVE-2018-19556 | — | — | 1.0% | Nov 26, 2018 | zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the... |
| CVE-2018-19555 | — | — | 0.5% | Nov 26, 2018 | tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password. |
| CVE-2018-19554 | — | — | 0.6% | Nov 26, 2018 | An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldNa... |
| CVE-2018-19553 | — | — | 1.0% | Nov 26, 2018 | Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now