2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18247 | — | — | 0.6% | Dec 17, 2018 | Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter. |
| CVE-2018-18246 | — | — | 0.5% | Dec 17, 2018 | Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module... |
| CVE-2018-18245 | — | — | 2.6% | Dec 17, 2018 | Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered... |
| CVE-2018-20173 | — | — | 24.5% | Dec 17, 2018 | Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API. |
| CVE-2018-20170 | — | — | 1.1% | Dec 17, 2018 | OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster respon... |
| CVE-2018-20169 | MEDIUM | 6.8 | 0.6% | Dec 17, 2018 | An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading o... |
| CVE-2018-20168 | — | — | 0.3% | Dec 17, 2018 | Google gVisor before 2018-08-22 reuses a pagetable in a different level with the paging-structure cache intact, which al... |
| CVE-2018-20167 | — | — | 2.7% | Dec 17, 2018 | Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat ... |
| CVE-2018-20161 | — | — | 0.7% | Dec 15, 2018 | A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable camera... |
| CVE-2018-20159 | — | — | 9.9% | Dec 15, 2018 | i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allow... |
| CVE-2018-20157 | — | — | 1.7% | Dec 15, 2018 | The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zi... |
| CVE-2018-20156 | — | — | 1.5% | Dec 14, 2018 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to exec... |
| CVE-2018-20155 | — | — | 0.8% | Dec 14, 2018 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intende... |
| CVE-2018-20154 | — | — | 1.0% | Dec 14, 2018 | The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e... |
| CVE-2018-20153 | — | — | 2.5% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privil... |
| CVE-2018-20152 | — | — | 4.2% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted inp... |
| CVE-2018-20151 | — | — | 6.7% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler ... |
| CVE-2018-20150 | — | — | 5.1% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins. |
| CVE-2018-20149 | — | — | 3.4% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files ... |
| CVE-2018-20148 | — | — | 30.9% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted meta... |
| CVE-2018-20147 | — | — | 3.6% | Dec 14, 2018 | In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deletin... |
| CVE-2018-19007 | — | — | 3.9% | Dec 14, 2018 | In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration pa... |
| CVE-2018-1977 | MEDIUM | 5.3 | 1.9% | Dec 14, 2018 | IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability. A rem... |
| CVE-2018-1848 | MEDIUM | 6.1 | 1.3% | Dec 14, 2018 | IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2018-19413 | — | — | 1.1% | Dec 14, 2018 | A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive i... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now