2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-25045MEDIUM6.1Django REST framework (aka django-rest-framework) before 3.9.1 allows XSS because the default DRF Browsable API view tem...
CVE-2018-25039MEDIUM5.4A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been declared as problematic. This vulnerability affects ...
CVE-2018-25038MEDIUM5.4A vulnerability was found in Thomson TCW710 ST5D.10.05. It has been classified as problematic. This affects an unknown p...
CVE-2018-25037MEDIUM5.4A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this issue is some unk...
CVE-2018-25036MEDIUM5.4A vulnerability has been found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this vulnerabilit...
CVE-2018-25035MEDIUM5.4A vulnerability, which was classified as problematic, was found in Thomson TCW710 ST5D.10.05. Affected is an unknown fun...
CVE-2018-25034MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Thomson TCW710 ST5D.10.05. This issue affects so...
CVE-2018-25031MEDIUM4.3Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a...
CVE-2018-4478MEDIUM6.8A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update ...
CVE-2018-10228MEDIUM6.1Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows re...
CVE-2018-6125MEDIUM6.5Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to ob...
CVE-2018-16061MEDIUM6.1Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
CVE-2018-19957MEDIUM6.1A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero...
CVE-2018-17865MEDIUM6.1A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web scrip...
CVE-2018-17862MEDIUM6.1A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web...
CVE-2018-17861MEDIUM6.1A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrar...
CVE-2018-16499MEDIUM5.9In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and t...
CVE-2018-16498MEDIUM5.5In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configu...
CVE-2018-16496MEDIUM5.3In Versa Director, the un-authentication request found.
CVE-2018-25007MEDIUM4.3Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0...
CVE-2018-19942MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect earlier versions of File Station. If exploited, t...
CVE-2018-25008MEDIUM5.9In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchroniz...
CVE-2018-1109MEDIUM5.3A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vuln...
CVE-2018-1107MEDIUM5.3It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON f...
CVE-2018-25004MEDIUM4.9A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain co...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now