2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-18018 | — | — | 2.2% | Apr 15, 2019 | SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slide... |
| CVE-2018-18017 | — | — | 1.0% | Apr 15, 2019 | XSS exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galle... |
| CVE-2018-16967 | — | — | 1.4% | Apr 15, 2019 | There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_roo... |
| CVE-2018-16966 | — | — | 0.9% | Apr 15, 2019 | There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_roo... |
| CVE-2018-17586 | — | — | 1.4% | Apr 15, 2019 | The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pag... |
| CVE-2018-17585 | — | — | 1.4% | Apr 15, 2019 | The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or ... |
| CVE-2018-17584 | — | — | 0.9% | Apr 15, 2019 | The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page. |
| CVE-2018-17583 | — | — | 1.4% | Apr 15, 2019 | The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pag... |
| CVE-2018-18261 | — | — | 0.8% | Apr 15, 2019 | In waimai Super Cms 20150505, there is an XSS vulnerability via the /admin.php/Foodcat/addsave fcname parameter. |
| CVE-2018-16259 | — | — | 0.9% | Apr 12, 2019 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE... |
| CVE-2018-16258 | — | — | 0.9% | Apr 12, 2019 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The v... |
| CVE-2018-16257 | — | — | 0.9% | Apr 12, 2019 | There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor... |
| CVE-2018-16256 | — | — | 0.9% | Apr 12, 2019 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The... |
| CVE-2018-16255 | — | — | 0.9% | Apr 12, 2019 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states t... |
| CVE-2018-16254 | — | — | 0.9% | Apr 12, 2019 | There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states th... |
| CVE-2018-13137 | — | — | 1.2% | Apr 12, 2019 | The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin... |
| CVE-2018-6269 | — | — | 0.3% | Apr 12, 2019 | NVIDIA Jetson TX2 contains a vulnerability in the kernel driver where input/output control (IOCTL) handling for user mod... |
| CVE-2018-6239 | — | — | 0.4% | Apr 12, 2019 | NVIDIA Jetson TX2 contains a vulnerability by means of speculative execution where local and unprivileged code may acces... |
| CVE-2018-20487 | — | — | 1.9% | Apr 11, 2019 | An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC ... |
| CVE-2018-19202 | — | — | 0.8% | Apr 11, 2019 | A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via... |
| CVE-2018-17305 | — | — | 1.5% | Apr 11, 2019 | UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even ad... |
| CVE-2018-19300 | — | — | 74.3% | Apr 11, 2019 | On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) bef... |
| CVE-2018-14683 | — | — | 0.6% | Apr 10, 2019 | PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI. |
| CVE-2018-20321 | — | — | 1.8% | Apr 10, 2019 | An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount th... |
| CVE-2018-1356 | — | — | 0.9% | Apr 9, 2019 | A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execut... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now