2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-16148The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerabl...
CVE-2018-16147The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulner...
CVE-2018-16146The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated a...
CVE-2018-16145The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before ...
CVE-2018-16144The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vuln...
CVE-2018-15918An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permission...
CVE-2018-15917Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HT...
CVE-2018-15684An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictab...
CVE-2018-15683An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect d...
CVE-2018-15682An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to auto...
CVE-2018-15681An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable...
CVE-2018-15680An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsal...
CVE-2018-15679An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?...
CVE-2018-15678An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=sig...
CVE-2018-15677The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is ...
CVE-2018-15676An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_pr...
CVE-2018-14771VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via even...
CVE-2018-14770VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ...
CVE-2018-14769VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.
CVE-2018-16546Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows...
CVE-2018-16437Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.
CVE-2018-16436Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.
CVE-2018-16545Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve a...
CVE-2018-14618HIGH7.5curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl...
CVE-2018-16543In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now