2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10736 | — | — | 42.6% | May 16, 2018 | A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter. |
| CVE-2018-10735 | — | — | 42.6% | May 16, 2018 | A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter. |
| CVE-2018-10123 | — | — | 10.9% | May 16, 2018 | p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via reques... |
| CVE-2018-8841 | — | — | 0.4% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-7505 | — | — | 2.9% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-7503 | — | — | 2.6% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-7501 | — | — | 1.7% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-7497 | — | — | 2.9% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-7495 | — | — | 2.2% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-10591 | — | — | 0.6% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-10590 | — | — | 1.7% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-10589 | — | — | 4.1% | May 15, 2018 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio... |
| CVE-2018-1262 | — | — | 1.3% | May 15, 2018 | Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation ac... |
| CVE-2018-11094 | — | — | 35.6% | May 15, 2018 | An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/Rebo... |
| CVE-2018-11127 | — | — | 0.5% | May 15, 2018 | e107 2.1.7 has CSRF resulting in arbitrary user deletion. |
| CVE-2018-11126 | — | — | 0.7% | May 15, 2018 | dg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account. |
| CVE-2018-11125 | — | — | — | May 15, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-11105 | — | — | 1.1% | May 15, 2018 | There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka ... |
| CVE-2018-3661 | — | — | 0.3% | May 15, 2018 | Buffer overflow in Intel system Configuration utilities selview.exe and syscfg.exe before version 14 build 11 allows a l... |
| CVE-2018-3611 | — | — | 1.6% | May 15, 2018 | Bounds check vulnerability in User Mode Driver in Intel Graphics Driver 15.40.x.4 and 21.20.x.x allows unprivileged user... |
| CVE-2018-1131 | — | — | 1.3% | May 15, 2018 | Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurat... |
| CVE-2018-10825 | — | — | 0.2% | May 15, 2018 | Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turt... |
| CVE-2018-11102 | — | — | 2.6% | May 15, 2018 | An issue was discovered in Libav 12.3. A read access violation in the mov_probe function in libavformat/mov.c allows rem... |
| CVE-2018-11100 | — | — | 1.8% | May 15, 2018 | The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a fi... |
| CVE-2018-11098 | — | — | 1.4% | May 15, 2018 | An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/uplo... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now