2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

CVE IDSeverityCVSSDescription
CVE-2018-15852Technicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of ran...
CVE-2018-15851An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user...
CVE-2018-15850An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via ind...
CVE-2018-15849An issue was discovered in portfolioCMS 1.0.5. There is CSRF to update the website settings via admin/aboutus.php.
CVE-2018-15848An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true.
CVE-2018-15847An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field...
CVE-2018-15846An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator'...
CVE-2018-15845There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
CVE-2018-15844An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas...
CVE-2018-15843GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
CVE-2018-15842WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
CVE-2018-15875MEDIUM6.1Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the ...
CVE-2018-15874MEDIUM6.1Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into th...
CVE-2018-15871An invalid memory address dereference was discovered in decompileSingleArgBuiltInFunctionCall in libming 0.4.8 before 20...
CVE-2018-15870An invalid memory address dereference was discovered in decompileGETVARIABLE in libming 0.4.8 before 2018-03-12. The vul...
CVE-2018-15869An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and th...
CVE-2018-14059Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, ...
CVE-2018-15576An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited...
CVE-2018-11654HIGH7.5Information disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker...
CVE-2018-11653CRITICAL9.8Information disclosure in Netwave IP camera at //etc/RT2870STA.dat (via HTTP on port 8000) allows an unauthenticated att...
CVE-2018-11502An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t...
CVE-2018-3786CRITICAL9.8A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously ...
CVE-2018-15728Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authentic...
CVE-2018-15605An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacke...
CVE-2018-15536/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now