2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-18382Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can ...
CVE-2018-18381MEDIUM5.4Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type...
CVE-2018-18377goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which ...
CVE-2018-18376goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about current...
CVE-2018-18375goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, an...
CVE-2018-18374XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
CVE-2018-18260In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can b...
CVE-2018-18259Stored XSS has been discovered in version 1.0.12 of the LUYA CMS software via /admin/api-cms-nav/create-page.
CVE-2018-17980NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo...
CVE-2018-17534Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper acc...
CVE-2018-17533Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlog...
CVE-2018-17532Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulne...
CVE-2018-15540Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse t...
CVE-2018-15539Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc...
CVE-2018-15538Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
CVE-2018-12154Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5...
CVE-2018-15378A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition...
CVE-2018-18073MEDIUM6.3Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators...
CVE-2018-17961Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err...
CVE-2018-15593An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c...
CVE-2018-15592An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c...
CVE-2018-15591An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c...
CVE-2018-15590An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security...
CVE-2018-18361An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as d...
CVE-2018-1747HIGH7.1IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now