2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17002 | — | — | 1.0% | Sep 21, 2018 | On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a... |
| CVE-2018-17001 | — | — | 1.0% | Sep 21, 2018 | On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding... |
| CVE-2018-16965 | — | — | 2.5% | Sep 21, 2018 | In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceCo... |
| CVE-2018-16833 | — | — | 65.4% | Sep 21, 2018 | Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBRE... |
| CVE-2018-16822 | — | — | 1.2% | Sep 21, 2018 | SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter. |
| CVE-2018-16821 | — | — | 1.0% | Sep 21, 2018 | SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests. |
| CVE-2018-14732 | — | — | 2.4% | Sep 21, 2018 | An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's cod... |
| CVE-2018-14731 | — | — | 2.3% | Sep 21, 2018 | An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because t... |
| CVE-2018-13111 | — | — | 0.9% | Sep 21, 2018 | There exists a partial Denial of Service vulnerability in Wanscam HW0021 IP Cameras. An attacker could craft a malicious... |
| CVE-2018-12511 | — | — | 0.9% | Sep 21, 2018 | In the mintToken function of a smart contract implementation for Substratum (SUB), an Ethereum ERC20 token, the administ... |
| CVE-2018-9282 | — | — | 0.7% | Sep 21, 2018 | An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vu... |
| CVE-2018-16793 | — | — | 11.3% | Sep 21, 2018 | Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parame... |
| CVE-2018-16597 | — | — | 0.5% | Sep 21, 2018 | An issue was discovered in the Linux kernel before 4.8. Incorrect access checking in overlayfs mounts could be used by l... |
| CVE-2018-16281 | — | — | 1.2% | Sep 21, 2018 | The DEISER "Profields - Project Custom Fields" app before 6.0.2 for Jira has Incorrect Access Control. |
| CVE-2018-14691 | — | — | 0.7% | Sep 21, 2018 | An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulne... |
| CVE-2018-14690 | — | — | 0.7% | Sep 21, 2018 | An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerab... |
| CVE-2018-14689 | — | — | 0.7% | Sep 21, 2018 | An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vul... |
| CVE-2018-14688 | — | — | 0.7% | Sep 21, 2018 | An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerab... |
| CVE-2018-11352 | — | — | 0.7% | Sep 21, 2018 | The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored withi... |
| CVE-2018-16786 | — | — | 0.7% | Sep 21, 2018 | DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php. |
| CVE-2018-16784 | — | — | 2.3% | Sep 21, 2018 | DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring... |
| CVE-2018-11241 | — | — | 3.7% | Sep 21, 2018 | An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary f... |
| CVE-2018-11240 | — | — | 2.3% | Sep 21, 2018 | An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' fea... |
| CVE-2018-8023 | — | — | 3.1% | Sep 21, 2018 | Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Ap... |
| CVE-2018-1685 | — | — | 0.4% | Sep 21, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now