2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14849 | — | — | 0.7% | Aug 13, 2018 | Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/pars... |
| CVE-2018-13417 | — | — | 20.7% | Aug 13, 2018 | In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External E... |
| CVE-2018-13415 | — | — | 31.8% | Aug 13, 2018 | In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External En... |
| CVE-2018-12587 | — | — | 0.8% | Aug 13, 2018 | A cross-site scripting (XSS) vulnerability was found in valeuraddons German Spelling Dictionary v1.3 (an Opera Browser a... |
| CVE-2018-10842 | — | — | — | Aug 13, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10912. Reason: This candidate is a duplicate of ... |
| CVE-2018-10569 | — | — | 0.9% | Aug 13, 2018 | An issue was discovered in Edimax EW-7438RPn Mini v2 before version 1.26. There is XSS in an SSID field. |
| CVE-2018-6414 | — | — | 2.5% | Aug 13, 2018 | A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially cr... |
| CVE-2018-5925 | — | — | 10.9% | Aug 13, 2018 | A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affe... |
| CVE-2018-5924 | — | — | 12.2% | Aug 13, 2018 | A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affe... |
| CVE-2018-13392 | — | — | 1.7% | Aug 13, 2018 | Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML... |
| CVE-2018-0714 | — | — | 2.3% | Aug 13, 2018 | Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 buil... |
| CVE-2018-3774 | — | — | 3.8% | Aug 12, 2018 | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open ... |
| CVE-2018-3110 | — | — | 2.5% | Aug 10, 2018 | A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected ... |
| CVE-2018-3779 | — | — | 6.1% | Aug 10, 2018 | active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containin... |
| CVE-2018-11063 | — | — | 0.3% | Aug 10, 2018 | Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software instal... |
| CVE-2018-14785 | — | — | 2.2% | Aug 10, 2018 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the devi... |
| CVE-2018-14784 | — | — | 1.0% | Aug 10, 2018 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable ... |
| CVE-2018-14783 | — | — | 0.7% | Aug 10, 2018 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forg... |
| CVE-2018-14782 | — | — | 1.6% | Aug 10, 2018 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access ... |
| CVE-2018-13341 | — | — | 3.6% | Aug 10, 2018 | Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for spe... |
| CVE-2018-10630 | — | — | 10.9% | Aug 10, 2018 | For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped wi... |
| CVE-2018-15191 | — | — | 1.1% | Aug 10, 2018 | PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript ... |
| CVE-2018-15190 | — | — | 0.5% | Aug 10, 2018 | PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field. |
| CVE-2018-7754 | — | — | 0.4% | Aug 10, 2018 | The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users... |
| CVE-2018-14837 | — | — | 0.7% | Aug 10, 2018 | Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now