2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19318 | — | — | 0.5% | Nov 16, 2018 | SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super admini... |
| CVE-2018-19312 | — | — | 1.9% | Nov 16, 2018 | Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to th... |
| CVE-2018-19311 | — | — | 1.2% | Nov 16, 2018 | Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated... |
| CVE-2018-18806 | — | — | 1.6% | Nov 16, 2018 | School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb. |
| CVE-2018-18805 | CRITICAL | 9.8 | 5.2% | Nov 16, 2018 | Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. |
| CVE-2018-18804 | — | — | 3.2% | Nov 16, 2018 | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. |
| CVE-2018-18803 | — | — | 3.2% | Nov 16, 2018 | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb... |
| CVE-2018-18801 | — | — | 3.2% | Nov 16, 2018 | The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=... |
| CVE-2018-18799 | — | — | 2.4% | Nov 16, 2018 | School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos. |
| CVE-2018-18797 | — | — | 2.4% | Nov 16, 2018 | School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php. |
| CVE-2018-18796 | — | — | 1.6% | Nov 16, 2018 | Library Management System 1.0 has SQL Injection via the "Search for Books" screen. |
| CVE-2018-18795 | — | — | 3.2% | Nov 16, 2018 | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. |
| CVE-2018-18794 | — | — | 2.4% | Nov 16, 2018 | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. |
| CVE-2018-18793 | — | — | 9.5% | Nov 16, 2018 | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. |
| CVE-2018-18763 | — | — | 3.2% | Nov 16, 2018 | SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. |
| CVE-2018-18761 | CRITICAL | 9.8 | 16.5% | Nov 16, 2018 | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. |
| CVE-2018-18760 | — | — | 2.6% | Nov 16, 2018 | RhinOS 3.0 build 1190 allows CSRF. |
| CVE-2018-18759 | — | — | 8.8% | Nov 16, 2018 | Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow. |
| CVE-2018-18756 | — | — | 1.5% | Nov 16, 2018 | Local Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008. |
| CVE-2018-18755 | CRITICAL | 9.8 | 3.1% | Nov 16, 2018 | K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up... |
| CVE-2018-16396 | — | — | 8.0% | Nov 16, 2018 | An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. I... |
| CVE-2018-16395 | — | — | 10.7% | Nov 16, 2018 | An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x b... |
| CVE-2018-15693 | — | — | 0.6% | Nov 16, 2018 | Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure di... |
| CVE-2018-15692 | — | — | 0.5% | Nov 16, 2018 | Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipu... |
| CVE-2018-7363 | MEDIUM | 4.3 | 0.9% | Nov 16, 2018 | All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since app... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now