2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12529 | — | — | 0.9% | Jul 2, 2018 | An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabil... |
| CVE-2018-12528 | — | — | 1.5% | Jul 2, 2018 | An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for ... |
| CVE-2018-12499 | — | — | 0.5% | Jul 2, 2018 | The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM)... |
| CVE-2018-10076 | — | — | 1.3% | Jul 2, 2018 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remo... |
| CVE-2018-10075 | — | — | 1.3% | Jul 2, 2018 | Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject ... |
| CVE-2018-13056 | — | — | 1.3% | Jul 2, 2018 | An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its ... |
| CVE-2018-13054 | — | — | 2.2% | Jul 2, 2018 | An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows conf... |
| CVE-2018-8039 | — | — | 10.4% | Jul 2, 2018 | It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.... |
| CVE-2018-13053 | — | — | 0.5% | Jul 2, 2018 | The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow v... |
| CVE-2018-0499 | — | — | 1.5% | Jul 2, 2018 | A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists ... |
| CVE-2018-13050 | — | — | 38.2% | Jul 2, 2018 | A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_usernam... |
| CVE-2018-13049 | — | — | 1.2% | Jul 2, 2018 | The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by t... |
| CVE-2018-13043 | — | — | 2.5% | Jul 1, 2018 | scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YA... |
| CVE-2018-13040 | — | — | 0.7% | Jul 1, 2018 | OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.p... |
| CVE-2018-13039 | — | — | 0.9% | Jul 1, 2018 | OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI. |
| CVE-2018-13038 | — | — | 1.8% | Jul 1, 2018 | OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. Thi... |
| CVE-2018-13037 | — | — | 1.6% | Jul 1, 2018 | An issue was discovered in jpeg-compressor 0.1. The bmp_load function in stb_image.c allows remote attackers to cause a ... |
| CVE-2018-13033 | — | — | 3.1% | Jul 1, 2018 | The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to c... |
| CVE-2018-13032 | — | — | 2.3% | Jul 1, 2018 | ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi... |
| CVE-2018-12990 | — | — | 1.2% | Jun 30, 2018 | phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field. |
| CVE-2018-13030 | — | — | 1.6% | Jun 30, 2018 | An issue was discovered in jpeg-compressor 0.1. The build_huffman function in stb_image.c allows remote attackers to cau... |
| CVE-2018-13026 | — | — | 1.6% | Jun 30, 2018 | An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GP... |
| CVE-2018-13025 | — | — | 0.8% | Jun 29, 2018 | protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via... |
| CVE-2018-13024 | — | — | 1.4% | Jun 29, 2018 | Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter t... |
| CVE-2018-13021 | — | — | 2.2% | Jun 29, 2018 | An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code exe... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now