2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16148 | — | — | 1.3% | Sep 5, 2018 | The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerabl... |
| CVE-2018-16147 | — | — | 1.3% | Sep 5, 2018 | The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulner... |
| CVE-2018-16146 | — | — | 6.2% | Sep 5, 2018 | The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated a... |
| CVE-2018-16145 | — | — | 2.3% | Sep 5, 2018 | The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before ... |
| CVE-2018-16144 | — | — | 32.7% | Sep 5, 2018 | The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vuln... |
| CVE-2018-15918 | — | — | 2.9% | Sep 5, 2018 | An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permission... |
| CVE-2018-15917 | — | — | 6.5% | Sep 5, 2018 | Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HT... |
| CVE-2018-15684 | — | — | 1.0% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictab... |
| CVE-2018-15683 | — | — | 0.7% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect d... |
| CVE-2018-15682 | — | — | 0.5% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to auto... |
| CVE-2018-15681 | — | — | 0.8% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable... |
| CVE-2018-15680 | — | — | 0.8% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsal... |
| CVE-2018-15679 | — | — | 0.9% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?... |
| CVE-2018-15678 | — | — | 0.9% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=sig... |
| CVE-2018-15677 | — | — | 0.5% | Sep 5, 2018 | The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is ... |
| CVE-2018-15676 | — | — | 0.9% | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_pr... |
| CVE-2018-14771 | — | — | 3.0% | Sep 5, 2018 | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via even... |
| CVE-2018-14770 | — | — | 3.0% | Sep 5, 2018 | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ... |
| CVE-2018-14769 | — | — | 0.5% | Sep 5, 2018 | VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF. |
| CVE-2018-16546 | — | — | 1.0% | Sep 5, 2018 | Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows... |
| CVE-2018-16437 | — | — | 1.6% | Sep 5, 2018 | Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator. |
| CVE-2018-16436 | — | — | 1.5% | Sep 5, 2018 | Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. |
| CVE-2018-16545 | — | — | 1.7% | Sep 5, 2018 | Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve a... |
| CVE-2018-14618 | HIGH | 7.5 | 10.8% | Sep 5, 2018 | curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl... |
| CVE-2018-16543 | — | — | 1.3% | Sep 5, 2018 | In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now