2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20328 | — | — | 0.7% | Dec 21, 2018 | Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated ... |
| CVE-2018-20327 | — | — | 0.6% | Dec 21, 2018 | Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies ... |
| CVE-2018-20318 | — | — | 1.7% | Dec 21, 2018 | An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWx... |
| CVE-2018-20191 | HIGH | 7.5 | 3.7% | Dec 20, 2018 | hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which ... |
| CVE-2018-20124 | MEDIUM | 5.5 | 0.5% | Dec 20, 2018 | hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with... |
| CVE-2018-19242 | — | — | 2.9% | Dec 20, 2018 | Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32 and TEW-673GRU devices allows attackers to hijack the contr... |
| CVE-2018-19241 | — | — | 2.3% | Dec 20, 2018 | Buffer overflow in video.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.... |
| CVE-2018-19240 | — | — | 3.7% | Dec 20, 2018 | Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.... |
| CVE-2018-19239 | — | — | 5.1% | Dec 20, 2018 | TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the tim... |
| CVE-2018-19134 | — | — | 2.9% | Dec 20, 2018 | In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafte... |
| CVE-2018-18767 | — | — | 0.6% | Dec 20, 2018 | An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g.,... |
| CVE-2018-18629 | — | — | 1.5% | Dec 20, 2018 | An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search pa... |
| CVE-2018-18442 | — | — | 1.3% | Dec 20, 2018 | D-Link DCS-825L devices with firmware 1.08 do not employ a suitable mechanism to prevent denial-of-service (DoS) attacks... |
| CVE-2018-18441 | — | — | 1.9% | Dec 20, 2018 | D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices in... |
| CVE-2018-18399 | — | — | 2.8% | Dec 20, 2018 | SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 all... |
| CVE-2018-18388 | — | — | 1.5% | Dec 20, 2018 | eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to... |
| CVE-2018-16627 | — | — | 0.8% | Dec 20, 2018 | panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. |
| CVE-2018-14846 | — | — | 1.1% | Dec 20, 2018 | The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php. |
| CVE-2018-12651 | — | — | 0.9% | Dec 20, 2018 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied in... |
| CVE-2018-17247 | — | — | 1.4% | Dec 20, 2018 | Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a ... |
| CVE-2018-17246 | — | — | 82.3% | Dec 20, 2018 | Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with... |
| CVE-2018-17245 | — | — | 1.3% | Dec 20, 2018 | Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are us... |
| CVE-2018-17244 | — | — | 1.5% | Dec 20, 2018 | Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when ... |
| CVE-2018-20216 | HIGH | 7.5 | 3.9% | Dec 20, 2018 | QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishand... |
| CVE-2018-20126 | MEDIUM | 5.5 | 0.5% | Dec 20, 2018 | hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now