2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-16119 | — | — | 34.1% | Jun 20, 2019 | Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to exec... |
| CVE-2018-16553 | — | — | 2.6% | Jun 20, 2019 | In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin. |
| CVE-2018-16514 | — | — | 0.9% | Jun 20, 2019 | A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage... |
| CVE-2018-16251 | — | — | 0.9% | Jun 20, 2019 | A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu. No input pa... |
| CVE-2018-16250 | — | — | 0.6% | Jun 20, 2019 | The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information... |
| CVE-2018-16249 | — | — | 0.5% | Jun 20, 2019 | In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleT... |
| CVE-2018-9564 | — | — | 0.8% | Jun 19, 2019 | In llcp_util_parse_link_params of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. Thi... |
| CVE-2018-9563 | — | — | 0.8% | Jun 19, 2019 | In llcp_util_parse_cc of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. This could l... |
| CVE-2018-9561 | — | — | 0.8% | Jun 19, 2019 | In llcp_util_parse_connect of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. This co... |
| CVE-2018-16595 | — | — | 0.6% | Jun 19, 2019 | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices has a Buffer Overflow. |
| CVE-2018-16594 | — | — | 0.9% | Jun 19, 2019 | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal. |
| CVE-2018-16593 | — | — | 0.9% | Jun 19, 2019 | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection. |
| CVE-2018-17388 | — | — | 2.3% | Jun 19, 2019 | SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or ... |
| CVE-2018-17387 | — | — | 0.9% | Jun 19, 2019 | CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account. |
| CVE-2018-17386 | — | — | 2.3% | Jun 19, 2019 | SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to myd... |
| CVE-2018-17381 | — | — | 2.3% | Jun 19, 2019 | SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order p... |
| CVE-2018-17374 | — | — | 2.3% | Jun 19, 2019 | SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order paramet... |
| CVE-2018-17148 | — | — | 3.7% | Jun 19, 2019 | An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configura... |
| CVE-2018-17146 | — | — | 3.6% | Jun 19, 2019 | A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Inform... |
| CVE-2018-17079 | — | — | 0.8% | Jun 19, 2019 | An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area. |
| CVE-2018-16618 | — | — | 8.0% | Jun 19, 2019 | VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. I... |
| CVE-2018-16613 | — | — | 2.7% | Jun 19, 2019 | An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum... |
| CVE-2018-17842 | CRITICAL | 9.8 | 2.2% | Jun 19, 2019 | SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter. |
| CVE-2018-17841 | — | — | 2.3% | Jun 19, 2019 | SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter. |
| CVE-2018-17840 | — | — | 2.3% | Jun 19, 2019 | SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now