2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18382 | — | — | 2.7% | Oct 16, 2018 | Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can ... |
| CVE-2018-18381 | MEDIUM | 5.4 | 0.5% | Oct 16, 2018 | Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type... |
| CVE-2018-18377 | — | — | 0.9% | Oct 16, 2018 | goform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which ... |
| CVE-2018-18376 | — | — | 1.5% | Oct 16, 2018 | goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about current... |
| CVE-2018-18375 | — | — | 1.3% | Oct 16, 2018 | goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, an... |
| CVE-2018-18374 | — | — | 0.5% | Oct 16, 2018 | XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter. |
| CVE-2018-18260 | — | — | 1.0% | Oct 15, 2018 | In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can b... |
| CVE-2018-18259 | — | — | 1.0% | Oct 15, 2018 | Stored XSS has been discovered in version 1.0.12 of the LUYA CMS software via /admin/api-cms-nav/create-page. |
| CVE-2018-17980 | — | — | 4.6% | Oct 15, 2018 | NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo... |
| CVE-2018-17534 | — | — | 0.7% | Oct 15, 2018 | Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper acc... |
| CVE-2018-17533 | — | — | 2.0% | Oct 15, 2018 | Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlog... |
| CVE-2018-17532 | — | — | 71.3% | Oct 15, 2018 | Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulne... |
| CVE-2018-15540 | — | — | 2.3% | Oct 15, 2018 | Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse t... |
| CVE-2018-15539 | — | — | 0.6% | Oct 15, 2018 | Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc... |
| CVE-2018-15538 | — | — | 0.8% | Oct 15, 2018 | Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities. |
| CVE-2018-12154 | — | — | 0.5% | Oct 15, 2018 | Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5... |
| CVE-2018-15378 | — | — | 1.3% | Oct 15, 2018 | A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition... |
| CVE-2018-18073 | MEDIUM | 6.3 | 2.7% | Oct 15, 2018 | Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators... |
| CVE-2018-17961 | — | — | 10.0% | Oct 15, 2018 | Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err... |
| CVE-2018-15593 | — | — | 1.0% | Oct 15, 2018 | An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c... |
| CVE-2018-15592 | — | — | 0.6% | Oct 15, 2018 | An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c... |
| CVE-2018-15591 | — | — | 1.3% | Oct 15, 2018 | An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user c... |
| CVE-2018-15590 | — | — | 1.0% | Oct 15, 2018 | An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security... |
| CVE-2018-18361 | — | — | 0.8% | Oct 15, 2018 | An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as d... |
| CVE-2018-1747 | HIGH | 7.1 | 1.9% | Oct 15, 2018 | IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack ... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now