2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14708 | — | — | 1.3% | Dec 3, 2018 | An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers t... |
| CVE-2018-14707 | — | — | 27.8% | Dec 3, 2018 | Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated a... |
| CVE-2018-14706 | — | — | 17.1% | Dec 3, 2018 | System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows u... |
| CVE-2018-14704 | — | — | 0.7% | Dec 3, 2018 | Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute ... |
| CVE-2018-14703 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unau... |
| CVE-2018-14702 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unaut... |
| CVE-2018-14701 | — | — | 20.0% | Dec 3, 2018 | System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unau... |
| CVE-2018-14700 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauth... |
| CVE-2018-14699 | — | — | 29.4% | Dec 3, 2018 | System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unau... |
| CVE-2018-14698 | — | — | 0.7% | Dec 3, 2018 | Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attacker... |
| CVE-2018-14697 | — | — | 0.7% | Dec 3, 2018 | Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attacker... |
| CVE-2018-14696 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthen... |
| CVE-2018-14695 | — | — | 1.3% | Dec 3, 2018 | Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthen... |
| CVE-2018-6440 | — | — | 2.2% | Dec 3, 2018 | A vulnerability in the proxy service of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remo... |
| CVE-2018-6439 | HIGH | 7.8 | 0.3% | Dec 3, 2018 | A Vulnerability in the configdownload command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8... |
| CVE-2018-2515 | — | — | — | Dec 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-2815. Reason: This candidate is a duplicate of ... |
| CVE-2018-19836 | — | — | 0.8% | Dec 3, 2018 | In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), an... |
| CVE-2018-19835 | — | — | 0.7% | Dec 3, 2018 | Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter. |
| CVE-2018-19827 | — | — | 2.0% | Dec 3, 2018 | In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that ... |
| CVE-2018-19826 | — | — | 1.2% | Dec 3, 2018 | In inspect.cpp in LibSass 3.5.5, a high memory footprint caused by an endless loop (containing a Sass::Inspect::operator... |
| CVE-2018-19824 | — | — | 0.6% | Dec 3, 2018 | In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malici... |
| CVE-2018-16863 | HIGH | 7.3 | 1.2% | Dec 3, 2018 | It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of... |
| CVE-2018-1002009 | — | — | 2.6% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002008 | — | — | 2.6% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
| CVE-2018-1002007 | — | — | 2.6% | Dec 3, 2018 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now