2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11345 | — | — | 1.9% | May 22, 2018 | An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload sup... |
| CVE-2018-11344 | — | — | 1.5% | May 22, 2018 | A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify... |
| CVE-2018-11343 | — | — | 0.9% | May 22, 2018 | A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attac... |
| CVE-2018-11342 | — | — | 1.1% | May 22, 2018 | A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily spe... |
| CVE-2018-11341 | — | — | 2.2% | May 22, 2018 | Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via... |
| CVE-2018-11340 | — | — | 2.1% | May 22, 2018 | An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload... |
| CVE-2018-11339 | — | — | 4.0% | May 22, 2018 | An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment. |
| CVE-2018-11331 | — | — | 2.3% | May 21, 2018 | An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filet... |
| CVE-2018-11330 | — | — | 0.7% | May 21, 2018 | An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames... |
| CVE-2018-8010 | — | — | 3.9% | May 21, 2018 | This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in So... |
| CVE-2018-7268 | — | — | 0.6% | May 21, 2018 | MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information e... |
| CVE-2018-11320 | — | — | 1.4% | May 21, 2018 | In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive va... |
| CVE-2018-11096 | — | — | 0.5% | May 21, 2018 | Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the ta... |
| CVE-2018-11092 | — | — | 1.0% | May 21, 2018 | An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin not... |
| CVE-2018-8142 | — | — | 1.2% | May 21, 2018 | A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feat... |
| CVE-2018-11311 | — | — | 15.9% | May 20, 2018 | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack... |
| CVE-2018-11319 | — | — | 2.7% | May 20, 2018 | Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the c... |
| CVE-2018-11242 | — | — | 4.1% | May 20, 2018 | An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte... |
| CVE-2018-11315 | — | — | 0.8% | May 20, 2018 | The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS reb... |
| CVE-2018-11239 | — | — | 0.9% | May 19, 2018 | An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 to... |
| CVE-2018-4994 | — | — | 9.9% | May 19, 2018 | Adobe Connect versions 9.7.5 and earlier have an exploitable Authentication Bypass vulnerability. Successful exploitatio... |
| CVE-2018-4992 | — | — | 1.1% | May 19, 2018 | Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper input validation vu... |
| CVE-2018-4991 | — | — | 5.8% | May 19, 2018 | Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validat... |
| CVE-2018-4944 | — | — | 9.0% | May 19, 2018 | Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploita... |
| CVE-2018-4943 | — | — | 6.9% | May 19, 2018 | Adobe PhoneGap Push Plugin versions 1.8.0 and earlier have an exploitable Same-Origin Method Execution vulnerability. Su... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now