2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-14908 | — | — | 0.5% | Aug 3, 2018 | Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printin... |
| CVE-2018-14907 | — | — | 1.0% | Aug 3, 2018 | The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in St... |
| CVE-2018-14906 | — | — | 0.7% | Aug 3, 2018 | The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters. |
| CVE-2018-14905 | — | — | 0.7% | Aug 3, 2018 | The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter. |
| CVE-2018-14904 | — | — | 0.7% | Aug 3, 2018 | Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as de... |
| CVE-2018-14728 | — | — | 76.5% | Aug 3, 2018 | upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter. |
| CVE-2018-14715 | — | — | 1.3% | Aug 3, 2018 | The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game,... |
| CVE-2018-14504 | — | — | 1.6% | Aug 3, 2018 | An issue was discovered in manage_filter_edit_page.php in MantisBT 2.x through 2.15.0. A cross-site scripting (XSS) vuln... |
| CVE-2018-13055 | — | — | 1.5% | Aug 3, 2018 | A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.... |
| CVE-2018-12989 | — | — | 0.3% | Aug 3, 2018 | The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processe... |
| CVE-2018-12607 | — | — | 0.7% | Aug 3, 2018 | An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x... |
| CVE-2018-12606 | — | — | 0.7% | Aug 3, 2018 | An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x... |
| CVE-2018-12605 | — | — | 0.7% | Aug 3, 2018 | An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' ... |
| CVE-2018-14774 | — | — | 1.1% | Aug 3, 2018 | An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0... |
| CVE-2018-14574 | — | — | 25.5% | Aug 3, 2018 | django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect. |
| CVE-2018-13416 | — | — | 20.2% | Aug 3, 2018 | In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML Extern... |
| CVE-2018-5489 | — | — | 0.8% | Aug 3, 2018 | NetApp 7-Mode Transition Tool allows users with valid credentials to access functions and information which may have bee... |
| CVE-2018-14884 | — | — | 3.2% | Aug 3, 2018 | An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing... |
| CVE-2018-14883 | — | — | 8.7% | Aug 3, 2018 | An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integ... |
| CVE-2018-14877 | — | — | 0.5% | Aug 3, 2018 | An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywor... |
| CVE-2018-14876 | — | — | 0.9% | Aug 3, 2018 | An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can... |
| CVE-2018-14873 | — | — | 0.6% | Aug 3, 2018 | An issue was discovered in Rincewind 0.1. There is a cross-site scripting (XSS) vulnerability involving a p=account requ... |
| CVE-2018-14872 | — | — | 1.0% | Aug 3, 2018 | An issue was discovered in Rincewind 0.1. A reinstall vulnerability exists because the parameter p of index.php and anot... |
| CVE-2018-14858 | — | — | 1.5% | Aug 2, 2018 | An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_... |
| CVE-2018-14851 | — | — | 4.3% | Aug 2, 2018 | exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now