2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-25045 | MEDIUM | 6.1 | 0.6% | Jul 23, 2022 | Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view tem... |
| CVE-2018-25039 | MEDIUM | 5.4 | 0.5% | Jun 12, 2022 | A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects ... |
| CVE-2018-25038 | MEDIUM | 5.4 | 0.5% | Jun 12, 2022 | A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown p... |
| CVE-2018-25037 | MEDIUM | 5.4 | 0.5% | Jun 12, 2022 | A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this issue is some unk... |
| CVE-2018-25036 | MEDIUM | 5.4 | 0.5% | Jun 12, 2022 | A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerabilit... |
| CVE-2018-25035 | MEDIUM | 5.4 | 0.5% | Jun 12, 2022 | A vulnerability, which was classified as problematic, was found in Thomson TCW710 ST5D.10.05. Affected is an unknown fun... |
| CVE-2018-25034 | MEDIUM | 5.4 | 0.7% | Jun 12, 2022 | A vulnerability, which was classified as problematic, has been found in Thomson TCW710 ST5D.10.05. This issue affects so... |
| CVE-2018-25031 | MEDIUM | 4.3 | 42.3% | Mar 11, 2022 | Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a... |
| CVE-2018-4478 | MEDIUM | 6.8 | 0.3% | Dec 23, 2021 | A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update ... |
| CVE-2018-10228 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows re... |
| CVE-2018-6125 | MEDIUM | 6.5 | 0.6% | Nov 2, 2021 | Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to ob... |
| CVE-2018-16061 | MEDIUM | 6.1 | 4.0% | Oct 15, 2021 | Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php. |
| CVE-2018-19957 | MEDIUM | 6.1 | 0.7% | Sep 10, 2021 | A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero... |
| CVE-2018-17865 | MEDIUM | 6.1 | 0.7% | Aug 9, 2021 | A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web scrip... |
| CVE-2018-17862 | MEDIUM | 6.1 | 1.4% | Aug 9, 2021 | A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web... |
| CVE-2018-17861 | MEDIUM | 6.1 | 1.5% | Aug 9, 2021 | A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrar... |
| CVE-2018-16499 | MEDIUM | 5.9 | 0.3% | May 26, 2021 | In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and t... |
| CVE-2018-16498 | MEDIUM | 5.5 | 0.2% | May 26, 2021 | In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configu... |
| CVE-2018-16496 | MEDIUM | 5.3 | 0.7% | May 26, 2021 | In Versa Director, the un-authentication request found. |
| CVE-2018-25007 | MEDIUM | 4.3 | 0.6% | Apr 23, 2021 | Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0... |
| CVE-2018-19942 | MEDIUM | 6.1 | 0.7% | Apr 16, 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, t... |
| CVE-2018-25008 | MEDIUM | 5.9 | 1.1% | Apr 14, 2021 | In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchroniz... |
| CVE-2018-1109 | MEDIUM | 5.3 | 1.4% | Mar 30, 2021 | A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vuln... |
| CVE-2018-1107 | MEDIUM | 5.3 | 1.2% | Mar 30, 2021 | It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON f... |
| CVE-2018-25004 | MEDIUM | 4.9 | 1.0% | Mar 1, 2021 | A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain co... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now