2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18869EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php file...
CVE-2018-18868No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter...
CVE-2018-18867An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue...
CVE-2018-18854Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) bec...
CVE-2018-18853Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) bec...
CVE-2018-18850In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment ...
CVE-2018-8858If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may a...
CVE-2018-17933VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User a...
CVE-2018-17931If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be af...
CVE-2018-16468In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG elem...
CVE-2018-16467A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file passwo...
CVE-2018-16466Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting acces...
CVE-2018-16465Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provi...
CVE-2018-16464A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link sha...
CVE-2018-16463A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacke...
CVE-2018-16461A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via ...
CVE-2018-18281Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall s...
CVE-2018-17783A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 throu...
CVE-2018-17782A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through...
CVE-2018-10712The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str...
CVE-2018-10711The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str...
CVE-2018-10710The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str...
CVE-2018-10709The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str...
CVE-2018-10532An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discover...
CVE-2018-18842CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to e...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now