2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16732 | — | — | 0.5% | Sep 8, 2018 | \upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save. |
| CVE-2018-16731 | — | — | 1.5% | Sep 8, 2018 | CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg,... |
| CVE-2018-16730 | — | — | 0.7% | Sep 8, 2018 | \upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name. |
| CVE-2018-16725 | — | — | 0.7% | Sep 8, 2018 | An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id paramet... |
| CVE-2018-16724 | — | — | 1.2% | Sep 8, 2018 | An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index req... |
| CVE-2018-16715 | — | — | 0.9% | Sep 8, 2018 | An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %Pro... |
| CVE-2018-9283 | — | — | 0.8% | Sep 7, 2018 | An XSS issue was discovered in CremeCRM 1.6.12. It is affected by 10 stored Cross-Site Scripting (XSS) vulnerabilities i... |
| CVE-2018-16454 | — | — | 1.1% | Sep 7, 2018 | PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface cha... |
| CVE-2018-16363 | — | — | 1.4% | Sep 7, 2018 | The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_f... |
| CVE-2018-16059 | — | — | 29.8% | Sep 7, 2018 | Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par... |
| CVE-2018-15486 | — | — | 2.1% | Sep 7, 2018 | An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and Fi... |
| CVE-2018-15485 | — | — | 2.5% | Sep 7, 2018 | An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or auth... |
| CVE-2018-15484 | — | — | 7.7% | Sep 7, 2018 | An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is po... |
| CVE-2018-15483 | — | — | 1.9% | Sep 7, 2018 | An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Denial of Service can occur through the ope... |
| CVE-2018-15474 | — | — | 3.3% | Sep 7, 2018 | CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04... |
| CVE-2018-14398 | — | — | 0.7% | Sep 7, 2018 | An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header,... |
| CVE-2018-14397 | — | — | 0.5% | Sep 7, 2018 | An issue was discovered in Creme CRM 1.6.12. The organization creation page is affected by 9 stored cross-site scripting... |
| CVE-2018-14396 | — | — | 0.5% | Sep 7, 2018 | An issue was discovered in Creme CRM 1.6.12. The salesman creation page is affected by 10 stored cross-site scripting vu... |
| CVE-2018-12897 | — | — | 1.7% | Sep 7, 2018 | SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow. |
| CVE-2018-16710 | — | — | 2.1% | Sep 7, 2018 | OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP re... |
| CVE-2018-16709 | — | — | 2.1% | Sep 7, 2018 | Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V... |
| CVE-2018-16460 | — | — | 2.9% | Sep 7, 2018 | A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker co... |
| CVE-2018-16704 | — | — | 0.8% | Sep 7, 2018 | An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possibl... |
| CVE-2018-16703 | — | — | 1.5% | Sep 7, 2018 | A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple us... |
| CVE-2018-16667 | — | — | 0.3% | Sep 7, 2018 | An issue was discovered in Contiki-NG through 4.1. There is a buffer over-read in lookup in os/storage/antelope/lvm.c wh... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now