2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12973 | — | — | 0.8% | Jun 29, 2018 | An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI. |
| CVE-2018-12972 | — | — | 2.2% | Jun 29, 2018 | An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, ... |
| CVE-2018-12971 | — | — | 0.4% | Jun 29, 2018 | EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users. |
| CVE-2018-12938 | — | — | — | Jun 28, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17833. Reason: This candidate is a duplicate o... |
| CVE-2018-8016 | — | — | 2.3% | Jun 28, 2018 | The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all netwo... |
| CVE-2018-1351 | — | — | 1.2% | Jun 28, 2018 | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to e... |
| CVE-2018-12934 | — | — | 3.3% | Jun 28, 2018 | remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessi... |
| CVE-2018-12933 | — | — | 2.3% | Jun 28, 2018 | PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) o... |
| CVE-2018-12932 | — | — | 2.4% | Jun 28, 2018 | PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (heap-based buffer over... |
| CVE-2018-12931 | — | — | 0.4% | Jun 28, 2018 | ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out... |
| CVE-2018-12930 | — | — | 0.4% | Jun 28, 2018 | ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a sta... |
| CVE-2018-12929 | — | — | 0.4% | Jun 28, 2018 | ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-aft... |
| CVE-2018-12928 | — | — | 0.4% | Jun 28, 2018 | In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur d... |
| CVE-2018-12589 | — | — | 20.3% | Jun 28, 2018 | Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in ... |
| CVE-2018-11510 | — | — | 44.8% | Jun 28, 2018 | The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/... |
| CVE-2018-12927 | — | — | 1.4% | Jun 28, 2018 | Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via ... |
| CVE-2018-12926 | — | — | 1.4% | Jun 28, 2018 | Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the ... |
| CVE-2018-12925 | — | — | 1.5% | Jun 28, 2018 | Baseon Lantronix MSS devices do not require a password for TELNET access. |
| CVE-2018-12924 | — | — | 1.5% | Jun 28, 2018 | Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET serv... |
| CVE-2018-12921 | — | — | 1.4% | Jun 28, 2018 | Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a dire... |
| CVE-2018-5528 | — | — | 1.2% | Jun 27, 2018 | Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4... |
| CVE-2018-5527 | — | — | 2.6% | Jun 27, 2018 | On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client ... |
| CVE-2018-1355 | — | — | 1.6% | Jun 27, 2018 | An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and ... |
| CVE-2018-1354 | — | — | 1.7% | Jun 27, 2018 | An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, ... |
| CVE-2018-1306 | — | — | 43.9% | Jun 27, 2018 | The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now