2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19799 | — | — | 4.5% | Dec 26, 2018 | Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. |
| CVE-2018-19616 | — | — | 30.3% | Dec 26, 2018 | An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/rem... |
| CVE-2018-19615 | MEDIUM | 6.1 | 3.3% | Dec 26, 2018 | Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a t... |
| CVE-2018-19182 | — | — | 0.6% | Dec 26, 2018 | Engelsystem before commit hash 2e28336 allows CSRF. |
| CVE-2018-18537 | — | — | 0.5% | Dec 26, 2018 | The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbi... |
| CVE-2018-18536 | — | — | 0.6% | Dec 26, 2018 | The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data ... |
| CVE-2018-18535 | — | — | 0.6% | Dec 26, 2018 | The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Spec... |
| CVE-2018-17987 | — | — | 0.9% | Dec 26, 2018 | The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain b... |
| CVE-2018-15518 | — | — | 2.5% | Dec 26, 2018 | QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML doc... |
| CVE-2018-11742 | CRITICAL | 9.8 | 14.3% | Dec 26, 2018 | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI. |
| CVE-2018-11741 | CRITICAL | 9.8 | 17.9% | Dec 26, 2018 | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure vi... |
| CVE-2018-20486 | — | — | 0.7% | Dec 26, 2018 | MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter. |
| CVE-2018-20485 | — | — | 5.3% | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. |
| CVE-2018-20484 | — | — | 5.3% | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. |
| CVE-2018-20483 | — | — | 0.7% | Dec 26, 2018 | set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata at... |
| CVE-2018-20482 | MEDIUM | 4.7 | 0.5% | Dec 26, 2018 | GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to c... |
| CVE-2018-0724 | — | — | 0.8% | Dec 26, 2018 | Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote ... |
| CVE-2018-0723 | — | — | 0.8% | Dec 26, 2018 | Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote ... |
| CVE-2018-17957 | LOW | 3.4 | 0.4% | Dec 26, 2018 | The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwo... |
| CVE-2018-20481 | — | — | 3.4% | Dec 26, 2018 | XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause ... |
| CVE-2018-20480 | — | — | 1.1% | Dec 26, 2018 | An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter. |
| CVE-2018-20479 | — | — | 1.1% | Dec 26, 2018 | An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter. |
| CVE-2018-20478 | — | — | 1.2% | Dec 26, 2018 | An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.p... |
| CVE-2018-20477 | — | — | 1.1% | Dec 26, 2018 | An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field. |
| CVE-2018-20476 | — | — | 0.7% | Dec 26, 2018 | An issue was discovered in S-CMS 3.0. It allows XSS via the admin/demo.php T_id parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now