2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16841 | MEDIUM | 6.5 | 4.6% | Nov 28, 2018 | Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configu... |
| CVE-2018-14629 | MEDIUM | 6.5 | 5.2% | Nov 28, 2018 | A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAM... |
| CVE-2018-19630 | — | — | 0.7% | Nov 28, 2018 | cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the... |
| CVE-2018-19621 | — | — | 0.4% | Nov 28, 2018 | server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team. |
| CVE-2018-19620 | — | — | 1.3% | Nov 28, 2018 | ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id. |
| CVE-2018-0721 | HIGH | 7.7 | 1.6% | Nov 27, 2018 | Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Syste... |
| CVE-2018-7988 | — | — | 0.2% | Nov 27, 2018 | There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently ... |
| CVE-2018-7977 | — | — | 1.0% | Nov 27, 2018 | There is an information leakage vulnerability on several Huawei products. Due to insufficient communication protection f... |
| CVE-2018-7961 | — | — | 0.9% | Nov 27, 2018 | There is a smart SMS verification code vulnerability in some Huawei smart phones. An attacker should trick a user to acc... |
| CVE-2018-7960 | — | — | 0.8% | Nov 27, 2018 | There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in... |
| CVE-2018-7959 | — | — | 0.8% | Nov 27, 2018 | There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-mid... |
| CVE-2018-7958 | — | — | 1.1% | Nov 27, 2018 | There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote att... |
| CVE-2018-7946 | — | — | 0.3% | Nov 27, 2018 | There is an information leak vulnerability in some Huawei smartphones. An attacker may do some specific configuration in... |
| CVE-2018-13418 | — | — | 5.2% | Nov 27, 2018 | System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "... |
| CVE-2018-13361 | — | — | 16.9% | Nov 27, 2018 | User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "m... |
| CVE-2018-13360 | — | — | 1.3% | Nov 27, 2018 | Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "fi... |
| CVE-2018-13359 | — | — | 19.9% | Nov 27, 2018 | Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "... |
| CVE-2018-13358 | — | — | 24.9% | Nov 27, 2018 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands v... |
| CVE-2018-13357 | — | — | 0.9% | Nov 27, 2018 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when view... |
| CVE-2018-13356 | — | — | 2.0% | Nov 27, 2018 | Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions. |
| CVE-2018-13355 | — | — | 1.1% | Nov 27, 2018 | Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups withou... |
| CVE-2018-13354 | — | — | 22.9% | Nov 27, 2018 | System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands v... |
| CVE-2018-13353 | — | — | 5.9% | Nov 27, 2018 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the ... |
| CVE-2018-13352 | — | — | 1.9% | Nov 27, 2018 | Session Exposure in the web application for TerraMaster TOS version 3.1.03 allows attackers to view active session token... |
| CVE-2018-13351 | — | — | 0.9% | Nov 27, 2018 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the e... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now