2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-15565 | — | — | 0.6% | Aug 20, 2018 | An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication... |
| CVE-2018-15564 | — | — | 0.5% | Aug 20, 2018 | An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any... |
| CVE-2018-15559 | — | — | 0.7% | Aug 20, 2018 | The editor in Xiuno BBS 4.0.4 allows stored XSS. |
| CVE-2018-15553 | — | — | 2.2% | Aug 20, 2018 | fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters i... |
| CVE-2018-15503 | — | — | 2.3% | Aug 18, 2018 | The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker ... |
| CVE-2018-15495 | — | — | 2.4% | Aug 18, 2018 | /filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url para... |
| CVE-2018-15494 | — | — | 2.6% | Aug 18, 2018 | In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. |
| CVE-2018-15492 | — | — | 1.2% | Aug 18, 2018 | A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes U... |
| CVE-2018-15491 | — | — | 1.0% | Aug 18, 2018 | A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.... |
| CVE-2018-15482 | — | — | 0.7% | Aug 17, 2018 | Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID... |
| CVE-2018-14982 | — | — | 0.6% | Aug 17, 2018 | Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is ... |
| CVE-2018-14981 | — | — | 0.6% | Aug 17, 2018 | Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The ... |
| CVE-2018-6622 | — | — | 0.5% | Aug 17, 2018 | An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an ob... |
| CVE-2018-15470 | — | — | 0.4% | Aug 17, 2018 | An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of eval... |
| CVE-2018-15469 | — | — | 0.4% | Aug 17, 2018 | An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor o... |
| CVE-2018-15468 | — | — | 0.3% | Aug 17, 2018 | An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtu... |
| CVE-2018-14058 | — | — | 28.9% | Aug 17, 2018 | Pimcore before 5.3.0 allows SQL Injection via the REST web service API. |
| CVE-2018-14057 | — | — | 3.3% | Aug 17, 2018 | Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati... |
| CVE-2018-1236 | — | — | — | Aug 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-11085 | — | — | — | Aug 17, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2018-15360 | — | — | 1.6% | Aug 17, 2018 | An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware ver... |
| CVE-2018-15359 | — | — | 1.6% | Aug 17, 2018 | An authenticated attacker with low privileges can use insecure sudo configuration to expand attack surface in Eltex ESP-... |
| CVE-2018-15358 | — | — | 1.3% | Aug 17, 2018 | An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in E... |
| CVE-2018-15357 | — | — | 1.1% | Aug 17, 2018 | An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmw... |
| CVE-2018-15356 | — | — | 2.5% | Aug 17, 2018 | An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now