2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16287 | — | — | 19.6% | Sep 14, 2018 | LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs. |
| CVE-2018-16286 | — | — | 21.5% | Sep 14, 2018 | LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sen... |
| CVE-2018-16242 | — | — | 0.7% | Sep 14, 2018 | oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism b... |
| CVE-2018-12585 | — | — | 1.6% | Sep 14, 2018 | An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service. |
| CVE-2018-12086 | — | — | 11.5% | Sep 14, 2018 | Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured req... |
| CVE-2018-10814 | — | — | 1.4% | Sep 14, 2018 | Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials. |
| CVE-2018-10763 | — | — | 1.7% | Sep 14, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2... |
| CVE-2018-17057 | — | — | 26.2% | Sep 14, 2018 | An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// ... |
| CVE-2018-0718 | — | — | 1.7% | Sep 14, 2018 | Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remo... |
| CVE-2018-17051 | — | — | 0.6% | Sep 14, 2018 | K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php. |
| CVE-2018-17049 | — | — | 0.6% | Sep 14, 2018 | CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action. |
| CVE-2018-17046 | — | — | 0.7% | Sep 14, 2018 | translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js. |
| CVE-2018-17045 | — | — | 0.5% | Sep 14, 2018 | An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator passw... |
| CVE-2018-17044 | — | — | 0.5% | Sep 14, 2018 | In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter. |
| CVE-2018-17043 | — | — | 1.1% | Sep 14, 2018 | An issue has been found in doc2txt through 2014-03-19. It is a heap-based buffer overflow in the function Storage::init ... |
| CVE-2018-17042 | — | — | 0.8% | Sep 14, 2018 | An issue has been found in dbf2txt through 2012-07-19. It is a infinite loop. |
| CVE-2018-17039 | — | — | 0.9% | Sep 14, 2018 | MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled... |
| CVE-2018-17037 | — | — | 1.0% | Sep 14, 2018 | user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superu... |
| CVE-2018-17035 | — | — | 1.1% | Sep 14, 2018 | UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter. |
| CVE-2018-17034 | — | — | 0.7% | Sep 14, 2018 | UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter. |
| CVE-2018-17031 | — | — | 0.9% | Sep 14, 2018 | In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstra... |
| CVE-2018-17030 | — | — | 2.3% | Sep 14, 2018 | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code v... |
| CVE-2018-17026 | — | — | 0.7% | Sep 13, 2018 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, ... |
| CVE-2018-17025 | — | — | 0.9% | Sep 13, 2018 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with... |
| CVE-2018-17024 | — | — | 0.7% | Sep 13, 2018 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now