2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-13350 | — | — | 16.7% | Nov 27, 2018 | SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" ... |
| CVE-2018-13349 | — | — | 1.1% | Nov 27, 2018 | Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows attackers to execute JavaSc... |
| CVE-2018-13338 | — | — | 10.2% | Nov 27, 2018 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands v... |
| CVE-2018-13336 | — | — | 9.1% | Nov 27, 2018 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands v... |
| CVE-2018-13335 | — | — | 0.9% | Nov 27, 2018 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when view... |
| CVE-2018-13333 | — | — | 1.1% | Nov 27, 2018 | Cross-site scripting in File Manager in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript in the per... |
| CVE-2018-13332 | — | — | 2.3% | Nov 27, 2018 | Directory Traversal in the explorer application in TerraMaster TOS version 3.1.03 allows attackers to upload files to ar... |
| CVE-2018-13331 | — | — | 1.1% | Nov 27, 2018 | Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when view... |
| CVE-2018-13330 | — | — | 8.1% | Nov 27, 2018 | System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands d... |
| CVE-2018-18982 | — | — | 60.8% | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b... |
| CVE-2018-17936 | — | — | 15.3% | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co... |
| CVE-2018-17934 | — | — | 19.7% | Nov 27, 2018 | NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be res... |
| CVE-2018-16130 | — | — | 24.0% | Nov 27, 2018 | System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary sys... |
| CVE-2018-14893 | — | — | 3.4% | Nov 27, 2018 | A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute syste... |
| CVE-2018-14892 | — | — | 0.9% | Nov 27, 2018 | Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow atta... |
| CVE-2018-13337 | — | — | 1.2% | Nov 27, 2018 | Session Fixation in the web application for TerraMaster TOS version 3.1.03 allows attackers to control users' session co... |
| CVE-2018-13334 | — | — | 1.1% | Nov 27, 2018 | Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "opt... |
| CVE-2018-13329 | — | — | 1.1% | Nov 27, 2018 | Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "l... |
| CVE-2018-13316 | — | — | 3.2% | Nov 27, 2018 | System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands vi... |
| CVE-2018-13314 | — | — | 3.2% | Nov 27, 2018 | System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands vi... |
| CVE-2018-13307 | — | — | 3.2% | Nov 27, 2018 | System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via th... |
| CVE-2018-13306 | — | — | 3.2% | Nov 27, 2018 | System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via t... |
| CVE-2018-13023 | — | — | 24.0% | Nov 27, 2018 | System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute ... |
| CVE-2018-13022 | — | — | 0.7% | Nov 27, 2018 | Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute... |
| CVE-2018-10142 | — | — | 2.2% | Nov 27, 2018 | The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operat... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now