2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-17423An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
CVE-2018-17399SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
CVE-2018-17398SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
CVE-2018-17393SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or ...
CVE-2018-17389CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
CVE-2018-15506In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity ...
CVE-2018-19878An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitatio...
CVE-2018-18863NGA ResourceLink 20.0.2.1 allows local file inclusion.
CVE-2018-18758Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-...
CVE-2018-18757Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than ...
CVE-2018-18472Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shel...
CVE-2018-18471/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has ...
CVE-2018-18425The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numeri...
CVE-2018-18406An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affect...
CVE-2018-18839An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "i...
CVE-2018-18838An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter...
CVE-2018-18837An issue was discovered in Netdata 1.10.0. HTTP Header Injection exists via the api/v1/data filename parameter because o...
CVE-2018-18836An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client...
CVE-2018-18802The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.
CVE-2018-18878In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, whi...
CVE-2018-18877In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative con...
CVE-2018-18876In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it po...
CVE-2018-18875In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allow...
CVE-2018-18852Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in...
CVE-2018-18944Artha ~ The Open Thesaurus 1.0.3.0 has a Buffer Overflow.

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now