2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-11345An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload sup...
CVE-2018-11344A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify...
CVE-2018-11343A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attac...
CVE-2018-11342A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily spe...
CVE-2018-11341Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via...
CVE-2018-11340An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload...
CVE-2018-11339An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
CVE-2018-11331An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filet...
CVE-2018-11330An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames...
CVE-2018-8010This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in So...
CVE-2018-7268MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information e...
CVE-2018-11320In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive va...
CVE-2018-11096Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the ta...
CVE-2018-11092An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin not...
CVE-2018-8142A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feat...
CVE-2018-11311A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack...
CVE-2018-11319Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the c...
CVE-2018-11242An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte...
CVE-2018-11315The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS reb...
CVE-2018-11239An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 to...
CVE-2018-4994Adobe Connect versions 9.7.5 and earlier have an exploitable Authentication Bypass vulnerability. Successful exploitatio...
CVE-2018-4992Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper input validation vu...
CVE-2018-4991Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validat...
CVE-2018-4944Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploita...
CVE-2018-4943Adobe PhoneGap Push Plugin versions 1.8.0 and earlier have an exploitable Same-Origin Method Execution vulnerability. Su...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now