2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18803 | — | — | 3.2% | Nov 16, 2018 | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb... |
| CVE-2018-18801 | — | — | 3.2% | Nov 16, 2018 | The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=... |
| CVE-2018-18799 | — | — | 2.4% | Nov 16, 2018 | School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. |
| CVE-2018-18797 | — | — | 2.4% | Nov 16, 2018 | School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. |
| CVE-2018-18796 | — | — | 1.6% | Nov 16, 2018 | Library Management System 1.0 has SQL Injection via the "Search for Books" screen. |
| CVE-2018-18795 | — | — | 3.2% | Nov 16, 2018 | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. |
| CVE-2018-18794 | — | — | 2.4% | Nov 16, 2018 | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. |
| CVE-2018-18793 | — | — | 9.5% | Nov 16, 2018 | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. |
| CVE-2018-18763 | — | — | 3.2% | Nov 16, 2018 | SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. |
| CVE-2018-18760 | — | — | 2.6% | Nov 16, 2018 | RhinOS 3.0 build 1190 allows CSRF. |
| CVE-2018-18759 | — | — | 8.8% | Nov 16, 2018 | Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow. |
| CVE-2018-18756 | — | — | 1.5% | Nov 16, 2018 | Local Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008. |
| CVE-2018-16396 | — | — | 8.0% | Nov 16, 2018 | An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. I... |
| CVE-2018-16395 | — | — | 10.7% | Nov 16, 2018 | An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x b... |
| CVE-2018-15693 | — | — | 0.6% | Nov 16, 2018 | Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure di... |
| CVE-2018-15692 | — | — | 0.5% | Nov 16, 2018 | Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipu... |
| CVE-2018-9086 | — | — | 2.4% | Nov 16, 2018 | In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download comman... |
| CVE-2018-9085 | — | — | 0.7% | Nov 16, 2018 | A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potenti... |
| CVE-2018-9073 | — | — | 0.5% | Nov 16, 2018 | Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain sec... |
| CVE-2018-9071 | — | — | 1.0% | Nov 16, 2018 | Lenovo Chassis Management Module (CMM) prior to version 2.0.0 allows unauthenticated users to retrieve information relat... |
| CVE-2018-19301 | — | — | 0.7% | Nov 15, 2018 | tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later v... |
| CVE-2018-18954 | — | — | 0.5% | Nov 15, 2018 | The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV... |
| CVE-2018-16620 | — | — | 1.1% | Nov 15, 2018 | Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control. |
| CVE-2018-16619 | — | — | 0.7% | Nov 15, 2018 | Sonatype Nexus Repository Manager before 3.14 allows XSS. |
| CVE-2018-14935 | — | — | 0.6% | Nov 15, 2018 | The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now