2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-13350SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" ...
CVE-2018-13349Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaSc...
CVE-2018-13338System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands v...
CVE-2018-13336System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands v...
CVE-2018-13335Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when view...
CVE-2018-13333Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript in the per...
CVE-2018-13332Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to ar...
CVE-2018-13331Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when view...
CVE-2018-13330System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands d...
CVE-2018-18982NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b...
CVE-2018-17936NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co...
CVE-2018-17934NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be res...
CVE-2018-16130System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary sys...
CVE-2018-14893A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute syste...
CVE-2018-14892Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow atta...
CVE-2018-13337Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session co...
CVE-2018-13334Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "opt...
CVE-2018-13329Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "l...
CVE-2018-13316System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands vi...
CVE-2018-13314System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands vi...
CVE-2018-13307System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via th...
CVE-2018-13306System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via t...
CVE-2018-13023System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute ...
CVE-2018-13022Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute...
CVE-2018-10142The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operat...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now