2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11750 | — | — | 1.1% | Oct 2, 2018 | Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As... |
| CVE-2018-11748 | — | — | 0.3% | Oct 2, 2018 | Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world ... |
| CVE-2018-17886 | — | — | 0.7% | Oct 2, 2018 | An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java ... |
| CVE-2018-17884 | — | — | 1.2% | Oct 2, 2018 | XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via th... |
| CVE-2018-17787 | — | — | 3.7% | Oct 2, 2018 | On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the PO... |
| CVE-2018-17786 | — | — | 4.1% | Oct 2, 2018 | On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not... |
| CVE-2018-17596 | — | — | 2.3% | Oct 2, 2018 | In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ... |
| CVE-2018-17595 | — | — | 1.0% | Oct 2, 2018 | In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /ba... |
| CVE-2018-17594 | — | — | 1.0% | Oct 2, 2018 | AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17593 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17591 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17590 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17589 | — | — | 1.0% | Oct 2, 2018 | AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17588 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-17587 | — | — | 2.3% | Oct 2, 2018 | AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter. |
| CVE-2018-16984 | — | — | 2.0% | Oct 2, 2018 | An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrar... |
| CVE-2018-15753 | — | — | 1.3% | Oct 2, 2018 | An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-code... |
| CVE-2018-15752 | — | — | 0.7% | Oct 2, 2018 | An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission... |
| CVE-2018-15563 | — | — | 0.7% | Oct 2, 2018 | _core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter. |
| CVE-2018-6262 | — | — | 0.2% | Oct 2, 2018 | NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user... |
| CVE-2018-6261 | — | — | 0.3% | Oct 2, 2018 | NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which sets incorrect permiss... |
| CVE-2018-1692 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1691 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1605 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
| CVE-2018-1601 | MEDIUM | 5.4 | 0.7% | Oct 2, 2018 | IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now