2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-19985 | — | — | 1.0% | Mar 21, 2019 | The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB d... |
| CVE-2018-19934 | — | — | 5.5% | Mar 21, 2019 | SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL ... |
| CVE-2018-19917 | — | — | 1.6% | Mar 21, 2019 | Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities. |
| CVE-2018-19872 | — | — | 1.4% | Mar 21, 2019 | An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp. |
| CVE-2018-19783 | — | — | 3.6% | Mar 21, 2019 | Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel. |
| CVE-2018-19694 | — | — | 1.6% | Mar 21, 2019 | HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form. |
| CVE-2018-19525 | — | — | 0.9% | Mar 21, 2019 | An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF ... |
| CVE-2018-19524 | — | — | 50.5% | Mar 21, 2019 | An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTB... |
| CVE-2018-19515 | — | — | 2.9% | Mar 21, 2019 | In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, ... |
| CVE-2018-19514 | — | — | 4.9% | Mar 21, 2019 | In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. ... |
| CVE-2018-19513 | — | — | 2.1% | Mar 21, 2019 | In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql... |
| CVE-2018-19512 | — | — | 7.4% | Mar 21, 2019 | In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary ... |
| CVE-2018-19511 | — | — | 0.7% | Mar 21, 2019 | wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change... |
| CVE-2018-19510 | — | — | 20.0% | Mar 21, 2019 | subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header. |
| CVE-2018-19509 | — | — | 1.1% | Mar 21, 2019 | wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with prope... |
| CVE-2018-19498 | — | — | 1.6% | Mar 21, 2019 | The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Server has XSS. |
| CVE-2018-19488 | — | — | 4.1% | Mar 21, 2019 | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() functi... |
| CVE-2018-19487 | — | — | 4.9% | Mar 21, 2019 | The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profi... |
| CVE-2018-19191 | — | — | 39.6% | Mar 21, 2019 | Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the... |
| CVE-2018-18882 | — | — | 0.7% | Mar 21, 2019 | A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data... |
| CVE-2018-18881 | — | — | 1.6% | Mar 21, 2019 | A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisiti... |
| CVE-2018-18862 | — | — | 2.9% | Mar 21, 2019 | BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demons... |
| CVE-2018-18849 | — | — | 0.6% | Mar 21, 2019 | In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value. |
| CVE-2018-18845 | — | — | 1.4% | Mar 21, 2019 | internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, ve... |
| CVE-2018-18798 | — | — | 3.2% | Mar 21, 2019 | Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.ph... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now