2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15697 | — | — | 0.9% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by ... |
| CVE-2018-15696 | — | — | 0.7% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts ... |
| CVE-2018-15695 | — | — | 1.0% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file ... |
| CVE-2018-15694 | — | — | 1.5% | Aug 27, 2018 | ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary lo... |
| CVE-2018-10938 | — | — | 5.0% | Aug 27, 2018 | A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotel... |
| CVE-2018-0715 | — | — | 3.1% | Aug 27, 2018 | Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inje... |
| CVE-2018-15899 | — | — | 0.9% | Aug 27, 2018 | An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability. |
| CVE-2018-15895 | — | — | 1.5% | Aug 27, 2018 | An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.cl... |
| CVE-2018-15894 | — | — | 1.5% | Aug 27, 2018 | A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=... |
| CVE-2018-15893 | — | — | 1.5% | Aug 27, 2018 | A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfr... |
| CVE-2018-15889 | — | — | — | Aug 26, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-5783. Reason: This candidate is a reservation du... |
| CVE-2018-15888 | — | — | 2.0% | Aug 26, 2018 | An issue was discovered in ASPCMS 2.5.6. When registering ordinary users in the addUser function of the /member/reg.asp ... |
| CVE-2018-15885 | — | — | 1.2% | Aug 26, 2018 | Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does no... |
| CVE-2018-15602 | — | — | 0.8% | Aug 26, 2018 | Zyxel VMG3312 B10B devices are affected by a persistent XSS vulnerability via the pages/connectionStatus/connectionStatu... |
| CVE-2018-15833 | — | — | 0.9% | Aug 26, 2018 | In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leadi... |
| CVE-2018-15876 | — | — | 0.9% | Aug 26, 2018 | An issue was discovered in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and passw... |
| CVE-2018-15864 | — | — | 0.4% | Aug 25, 2018 | Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local atta... |
| CVE-2018-15863 | — | — | 0.5% | Aug 25, 2018 | Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by ... |
| CVE-2018-15862 | — | — | 0.4% | Aug 25, 2018 | Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attacke... |
| CVE-2018-15861 | — | — | 0.5% | Aug 25, 2018 | Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attack... |
| CVE-2018-15859 | — | — | 0.5% | Aug 25, 2018 | Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 co... |
| CVE-2018-15858 | — | — | 0.4% | Aug 25, 2018 | Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon ... |
| CVE-2018-15857 | — | — | 0.4% | Aug 25, 2018 | An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local att... |
| CVE-2018-15856 | — | — | 0.4% | Aug 25, 2018 | An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 co... |
| CVE-2018-15855 | — | — | 0.4% | Aug 25, 2018 | Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereferen... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now