2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17591 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17590 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17589 | — | — | 1.0% | Oct 2, 2018 | AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17588 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17587 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-16984 | — | — | 2.0% | Oct 2, 2018 | An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrar... |
| CVE-2018-15753 | — | — | 1.3% | Oct 2, 2018 | An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-code... |
| CVE-2018-15752 | — | — | 0.7% | Oct 2, 2018 | An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission... |
| CVE-2018-15563 | — | — | 0.7% | Oct 2, 2018 | _core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter. |
| CVE-2018-6262 | — | — | 0.2% | Oct 2, 2018 | NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user... |
| CVE-2018-6261 | — | — | 0.3% | Oct 2, 2018 | NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which sets incorrect permiss... |
| CVE-2018-11043 | — | — | — | Oct 2, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-11072 | — | — | 0.4% | Oct 2, 2018 | Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability. A local authenticated malicious use... |
| CVE-2018-17874 | — | — | 0.6% | Oct 1, 2018 | ExpressionEngine before 4.3.5 has reflected XSS. |
| CVE-2018-17870 | — | — | 0.8% | Oct 1, 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open ... |
| CVE-2018-17869 | — | — | 0.5% | Oct 1, 2018 | DASAN H660GW devices do not implement any CSRF protection mechanism. |
| CVE-2018-17868 | — | — | 0.5% | Oct 1, 2018 | DASAN H660GW devices have Stored XSS in the Port Forwarding functionality. |
| CVE-2018-17867 | — | — | 3.8% | Oct 1, 2018 | The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell me... |
| CVE-2018-15702 | — | — | 0.5% | Oct 1, 2018 | The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the r... |
| CVE-2018-15701 | — | — | 0.6% | Oct 1, 2018 | The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated ... |
| CVE-2018-15700 | — | — | 0.6% | Oct 1, 2018 | The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated ... |
| CVE-2018-10605 | — | — | 1.5% | Oct 1, 2018 | Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system conf... |
| CVE-2018-14808 | — | — | 0.9% | Oct 1, 2018 | Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on ... |
| CVE-2018-14804 | — | — | 3.5% | Oct 1, 2018 | Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code exec... |
| CVE-2018-14802 | — | — | 3.6% | Oct 1, 2018 | Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA,... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now