2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18869 | — | — | 3.7% | Oct 31, 2018 | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php file... |
| CVE-2018-18868 | — | — | 0.7% | Oct 31, 2018 | No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter... |
| CVE-2018-18867 | — | — | 1.5% | Oct 31, 2018 | An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue... |
| CVE-2018-18854 | — | — | 1.9% | Oct 31, 2018 | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) bec... |
| CVE-2018-18853 | — | — | 1.9% | Oct 31, 2018 | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) bec... |
| CVE-2018-18850 | — | — | 12.5% | Oct 31, 2018 | In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment ... |
| CVE-2018-8858 | — | — | 1.2% | Oct 30, 2018 | If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may a... |
| CVE-2018-17933 | — | — | 1.2% | Oct 30, 2018 | VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User a... |
| CVE-2018-17931 | — | — | 0.4% | Oct 30, 2018 | If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be af... |
| CVE-2018-16468 | — | — | 0.9% | Oct 30, 2018 | In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG elem... |
| CVE-2018-16467 | — | — | 1.1% | Oct 30, 2018 | A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file passwo... |
| CVE-2018-16466 | — | — | 1.0% | Oct 30, 2018 | Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting acces... |
| CVE-2018-16465 | — | — | 0.8% | Oct 30, 2018 | Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provi... |
| CVE-2018-16464 | — | — | 0.9% | Oct 30, 2018 | A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link sha... |
| CVE-2018-16463 | — | — | 0.5% | Oct 30, 2018 | A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacke... |
| CVE-2018-16461 | — | — | 3.9% | Oct 30, 2018 | A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via ... |
| CVE-2018-18281 | — | — | 1.1% | Oct 30, 2018 | Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall s... |
| CVE-2018-17783 | — | — | 0.7% | Oct 30, 2018 | A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 throu... |
| CVE-2018-17782 | — | — | 0.7% | Oct 30, 2018 | A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through... |
| CVE-2018-10712 | — | — | 1.3% | Oct 30, 2018 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str... |
| CVE-2018-10711 | — | — | 1.5% | Oct 30, 2018 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str... |
| CVE-2018-10710 | — | — | 1.0% | Oct 30, 2018 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str... |
| CVE-2018-10709 | — | — | 1.2% | Oct 30, 2018 | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str... |
| CVE-2018-10532 | — | — | 2.4% | Oct 30, 2018 | An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discover... |
| CVE-2018-18842 | — | — | 0.8% | Oct 30, 2018 | CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to e... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now