2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18242youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=logi...
CVE-2018-12449The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.
CVE-2018-18240Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine co...
CVE-2018-18062An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remo...
CVE-2018-18061An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager int...
CVE-2018-17337Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast.
CVE-2018-13789An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of file...
CVE-2018-12596Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at...
CVE-2018-12456Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attacker...
CVE-2018-12455Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate...
CVE-2018-12544In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking ...
CVE-2018-12542In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that sho...
CVE-2018-12173Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before fi...
CVE-2018-12172Improper password hashing in firmware in Intel Server Board (S7200AP,S7200APR) and Intel Compute Module (HNS7200AP, HNS7...
CVE-2018-12161Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated ...
CVE-2018-12158Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a pri...
CVE-2018-12153Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5...
CVE-2018-12152Pointer corruption in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x....
CVE-2018-17925Multiple instances of this vulnerability (Unsafe ActiveX Control Marked Safe For Scripting) have been identified in the ...
CVE-2018-13805A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-...
CVE-2018-13802A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged...
CVE-2018-13801A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp a...
CVE-2018-13800A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface c...
CVE-2018-18211PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
CVE-2018-18210XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now