2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14941 | — | — | 1.0% | Aug 5, 2018 | Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for th... |
| CVE-2018-14940 | — | — | 1.3% | Aug 5, 2018 | PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and wi... |
| CVE-2018-14939 | — | — | 2.2% | Aug 5, 2018 | The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in... |
| CVE-2018-14938 | — | — | 2.8% | Aug 5, 2018 | An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the fun... |
| CVE-2018-14937 | — | — | 0.9% | Aug 5, 2018 | The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field. |
| CVE-2018-14936 | — | — | 0.9% | Aug 5, 2018 | The Add page option in my little forum 2.4.12 allows XSS via the Title field. |
| CVE-2018-14593 | — | — | 1.9% | Aug 4, 2018 | An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x throug... |
| CVE-2018-14541 | — | — | 0.7% | Aug 4, 2018 | PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, Sta... |
| CVE-2018-14497 | — | — | 1.6% | Aug 4, 2018 | Tenda D152 ADSL routers allow XSS via a crafted SSID. |
| CVE-2018-14473 | — | — | 3.1% | Aug 4, 2018 | OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be e... |
| CVE-2018-14417 | — | — | 89.6% | Aug 4, 2018 | A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul... |
| CVE-2018-12483 | — | — | 3.2% | Aug 4, 2018 | OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the co... |
| CVE-2018-12482 | — | — | 1.3% | Aug 4, 2018 | OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit ... |
| CVE-2018-14929 | — | — | 0.7% | Aug 3, 2018 | Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home ... |
| CVE-2018-14928 | — | — | 1.7% | Aug 3, 2018 | /contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file para... |
| CVE-2018-14927 | — | — | 1.5% | Aug 3, 2018 | Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application fold... |
| CVE-2018-14926 | — | — | 0.6% | Aug 3, 2018 | Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request. |
| CVE-2018-14925 | — | — | 1.5% | Aug 3, 2018 | Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegi... |
| CVE-2018-14924 | — | — | 0.8% | Aug 3, 2018 | Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nom... |
| CVE-2018-14923 | — | — | 1.4% | Aug 3, 2018 | A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via vid... |
| CVE-2018-5490 | — | — | 0.9% | Aug 3, 2018 | Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and ther... |
| CVE-2018-14912 | — | — | 93.2% | Aug 3, 2018 | cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned... |
| CVE-2018-14911 | — | — | 1.1% | Aug 3, 2018 | A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filt... |
| CVE-2018-14910 | — | — | 1.0% | Aug 3, 2018 | SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (... |
| CVE-2018-7748 | — | — | 2.6% | Aug 3, 2018 | report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now