2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17068 | — | — | 3.7% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2018-17067 | — | — | 1.9% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a... |
| CVE-2018-17066 | — | — | 7.3% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2018-17065 | — | — | 1.9% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a ... |
| CVE-2018-17064 | — | — | 7.4% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2018-17063 | — | — | 4.1% | Sep 15, 2018 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2018-17061 | — | — | 0.7% | Sep 15, 2018 | BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search res... |
| CVE-2018-16706 | — | — | 22.3% | Sep 14, 2018 | LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/devi... |
| CVE-2018-16288 | — | — | 35.3% | Sep 14, 2018 | LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. |
| CVE-2018-16287 | — | — | 19.6% | Sep 14, 2018 | LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs. |
| CVE-2018-16286 | — | — | 21.5% | Sep 14, 2018 | LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sen... |
| CVE-2018-16242 | — | — | 0.7% | Sep 14, 2018 | oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism b... |
| CVE-2018-12585 | — | — | 1.6% | Sep 14, 2018 | An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service. |
| CVE-2018-12086 | — | — | 11.5% | Sep 14, 2018 | Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured req... |
| CVE-2018-10814 | — | — | 1.4% | Sep 14, 2018 | Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials. |
| CVE-2018-10763 | — | — | 1.7% | Sep 14, 2018 | Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2... |
| CVE-2018-17057 | — | — | 26.2% | Sep 14, 2018 | An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// ... |
| CVE-2018-11087 | MEDIUM | 5.9 | 1.2% | Sep 14, 2018 | Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerabil... |
| CVE-2018-11058 | CRITICAL | 9.8 | 4.0% | Sep 14, 2018 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C... |
| CVE-2018-14638 | HIGH | 7.5 | 2.6% | Sep 14, 2018 | A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function ... |
| CVE-2018-1791 | MEDIUM | 4.9 | 1.0% | Sep 14, 2018 | IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation... |
| CVE-2018-1719 | MEDIUM | 5.9 | 2.4% | Sep 14, 2018 | IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This ... |
| CVE-2018-0718 | — | — | 1.7% | Sep 14, 2018 | Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remo... |
| CVE-2018-17051 | — | — | 0.6% | Sep 14, 2018 | K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php. |
| CVE-2018-17049 | — | — | 0.6% | Sep 14, 2018 | CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now