2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19990 | — | — | 5.3% | May 13, 2019 | In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-8... |
| CVE-2018-19989 | — | — | 5.5% | May 13, 2019 | In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 R... |
| CVE-2018-19988 | — | — | 7.4% | May 13, 2019 | In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilitie... |
| CVE-2018-19987 | — | — | 12.9% | May 13, 2019 | D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.... |
| CVE-2018-19986 | — | — | 41.6% | May 13, 2019 | In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DI... |
| CVE-2018-19048 | — | — | 1.5% | May 13, 2019 | Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element. |
| CVE-2018-18872 | — | — | 0.7% | May 13, 2019 | The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin... |
| CVE-2018-18524 | — | — | 1.9% | May 13, 2019 | Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inj... |
| CVE-2018-15128 | — | — | 5.2% | May 13, 2019 | An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.... |
| CVE-2018-19037 | — | — | 1.8% | May 13, 2019 | On Virgin Media wireless router 3.0 hub devices, the web interface is vulnerable to denial of service. When POST request... |
| CVE-2018-18558 | — | — | 0.4% | May 13, 2019 | An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of... |
| CVE-2018-16639 | — | — | 0.7% | May 13, 2019 | Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation. |
| CVE-2018-16626 | — | — | 0.7% | May 13, 2019 | index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name. |
| CVE-2018-16625 | — | — | 0.7% | May 13, 2019 | index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. |
| CVE-2018-16624 | — | — | 0.7% | May 13, 2019 | panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page. |
| CVE-2018-16623 | — | — | 0.7% | May 13, 2019 | Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropd... |
| CVE-2018-15530 | — | — | 0.7% | May 13, 2019 | Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom... |
| CVE-2018-14714 | — | — | 27.4% | May 13, 2019 | System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system co... |
| CVE-2018-14713 | — | — | 3.9% | May 13, 2019 | Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary... |
| CVE-2018-14712 | — | — | 4.2% | May 13, 2019 | Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via... |
| CVE-2018-14711 | — | — | 0.6% | May 13, 2019 | Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers... |
| CVE-2018-14710 | — | — | 5.3% | May 13, 2019 | Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript vi... |
| CVE-2018-12304 | — | — | 0.8% | May 13, 2019 | Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript vi... |
| CVE-2018-12303 | — | — | 0.6% | May 13, 2019 | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via direct... |
| CVE-2018-12302 | — | — | 0.8% | May 13, 2019 | Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to stea... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now