2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18242 | — | — | 1.1% | Oct 11, 2018 | youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=logi... |
| CVE-2018-12449 | — | — | 0.9% | Oct 11, 2018 | The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking. |
| CVE-2018-18240 | — | — | 3.7% | Oct 11, 2018 | Pippo through 1.11.0 allows remote code execution via a command to java.lang.ProcessBuilder because the XstreamEngine co... |
| CVE-2018-18062 | — | — | 0.8% | Oct 10, 2018 | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remo... |
| CVE-2018-18061 | — | — | 0.9% | Oct 10, 2018 | An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager int... |
| CVE-2018-17337 | — | — | 0.7% | Oct 10, 2018 | Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast. |
| CVE-2018-13789 | — | — | 1.2% | Oct 10, 2018 | An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of file... |
| CVE-2018-12596 | — | — | 22.4% | Oct 10, 2018 | Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at... |
| CVE-2018-12456 | — | — | 0.9% | Oct 10, 2018 | Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attacker... |
| CVE-2018-12455 | — | — | 5.0% | Oct 10, 2018 | Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate... |
| CVE-2018-12544 | — | — | 2.2% | Oct 10, 2018 | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking ... |
| CVE-2018-12542 | — | — | 2.3% | Oct 10, 2018 | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that sho... |
| CVE-2018-12173 | — | — | 0.4% | Oct 10, 2018 | Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before fi... |
| CVE-2018-12172 | — | — | 0.3% | Oct 10, 2018 | Improper password hashing in firmware in Intel Server Board (S7200AP,S7200APR) and Intel Compute Module (HNS7200AP, HNS7... |
| CVE-2018-12161 | — | — | 1.1% | Oct 10, 2018 | Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated ... |
| CVE-2018-12158 | — | — | 0.3% | Oct 10, 2018 | Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a pri... |
| CVE-2018-12153 | — | — | 0.4% | Oct 10, 2018 | Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5... |
| CVE-2018-12152 | — | — | 0.9% | Oct 10, 2018 | Pointer corruption in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.... |
| CVE-2018-17925 | — | — | 0.3% | Oct 10, 2018 | Multiple instances of this vulnerability (Unsafe ActiveX Control Marked Safe For Scripting) have been identified in the ... |
| CVE-2018-13805 | — | — | 1.5% | Oct 10, 2018 | A vulnerability has been identified in SIMATIC ET 200SP Open Controller (All versions >= V2.0 and < V2.1.6), SIMATIC S7-... |
| CVE-2018-13802 | — | — | 3.6% | Oct 10, 2018 | A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged... |
| CVE-2018-13801 | — | — | 2.7% | Oct 10, 2018 | A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp a... |
| CVE-2018-13800 | — | — | 0.6% | Oct 10, 2018 | A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface c... |
| CVE-2018-18211 | — | — | 0.9% | Oct 10, 2018 | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI. |
| CVE-2018-18210 | — | — | 0.9% | Oct 10, 2018 | XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now