2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12301 | — | — | 1.4% | May 13, 2019 | Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface... |
| CVE-2018-12300 | — | — | 2.7% | May 13, 2019 | Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in th... |
| CVE-2018-12299 | — | — | 0.6% | May 13, 2019 | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via upload... |
| CVE-2018-12298 | — | — | 1.7% | May 13, 2019 | Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's co... |
| CVE-2018-12297 | — | — | 0.7% | May 13, 2019 | Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via UR... |
| CVE-2018-12296 | — | — | 9.5% | May 13, 2019 | Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attac... |
| CVE-2018-12295 | — | — | 1.1% | May 13, 2019 | SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL com... |
| CVE-2018-20838 | — | — | 1.1% | May 13, 2019 | ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS. |
| CVE-2018-8812 | — | — | — | May 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-15610. Reason: This candidate is a reservation d... |
| CVE-2018-7120 | — | — | 2.1% | May 10, 2019 | A security vulnerability in the HPE Virtual Connect SE 16Gb Fibre Channel Module for HPE Synergy running firmware 5.00.5... |
| CVE-2018-7119 | — | — | 0.3% | May 10, 2019 | A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version S... |
| CVE-2018-7064 | — | — | 1.4% | May 10, 2019 | A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An at... |
| CVE-2018-7083 | — | — | 1.8% | May 10, 2019 | If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents... |
| CVE-2018-20837 | — | — | 0.7% | May 9, 2019 | include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS. |
| CVE-2018-5409 | — | — | 1.1% | May 8, 2019 | The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code withou... |
| CVE-2018-5408 | — | — | 0.7% | May 8, 2019 | The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly va... |
| CVE-2018-6634 | — | — | 1.5% | May 7, 2019 | A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized user... |
| CVE-2018-6243 | — | — | 0.2% | May 7, 2019 | NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of vi... |
| CVE-2018-20503 | — | — | 3.9% | May 7, 2019 | Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter. |
| CVE-2018-19456 | — | — | 1.8% | May 7, 2019 | The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive in... |
| CVE-2018-14485 | — | — | 16.3% | May 7, 2019 | BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. |
| CVE-2018-14478 | — | — | 1.0% | May 7, 2019 | ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient... |
| CVE-2018-18979 | — | — | 1.2% | May 6, 2019 | An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically ... |
| CVE-2018-18978 | — | — | 0.7% | May 6, 2019 | An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically ... |
| CVE-2018-18977 | — | — | 1.6% | May 6, 2019 | An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reve... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now