2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-17423 | — | — | 0.7% | Jun 19, 2019 | An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php. |
| CVE-2018-17399 | — | — | 2.3% | Jun 19, 2019 | SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter. |
| CVE-2018-17398 | — | — | 2.3% | Jun 19, 2019 | SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter. |
| CVE-2018-17393 | — | — | 2.3% | Jun 19, 2019 | SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or ... |
| CVE-2018-17389 | — | — | 0.9% | Jun 19, 2019 | CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account. |
| CVE-2018-15506 | — | — | 4.7% | Jun 19, 2019 | In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity ... |
| CVE-2018-19878 | — | — | 1.2% | Jun 19, 2019 | An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitatio... |
| CVE-2018-18863 | — | — | 1.5% | Jun 19, 2019 | NGA ResourceLink 20.0.2.1 allows local file inclusion. |
| CVE-2018-18758 | — | — | 2.3% | Jun 19, 2019 | Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-... |
| CVE-2018-18757 | — | — | 2.3% | Jun 19, 2019 | Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than ... |
| CVE-2018-18472 | — | — | 30.3% | Jun 19, 2019 | Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shel... |
| CVE-2018-18471 | — | — | 7.7% | Jun 19, 2019 | /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has ... |
| CVE-2018-18425 | — | — | 1.1% | Jun 19, 2019 | The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numeri... |
| CVE-2018-18406 | — | — | 2.0% | Jun 19, 2019 | An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affect... |
| CVE-2018-18839 | — | — | 1.9% | Jun 18, 2019 | An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "i... |
| CVE-2018-18838 | — | — | 2.2% | Jun 18, 2019 | An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter... |
| CVE-2018-18837 | — | — | 1.8% | Jun 18, 2019 | An issue was discovered in Netdata 1.10.0. HTTP Header Injection exists via the api/v1/data filename parameter because o... |
| CVE-2018-18836 | — | — | 2.0% | Jun 18, 2019 | An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client... |
| CVE-2018-18802 | — | — | 0.9% | Jun 18, 2019 | The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit. |
| CVE-2018-18878 | — | — | 2.9% | Jun 18, 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, whi... |
| CVE-2018-18877 | — | — | 1.7% | Jun 18, 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative con... |
| CVE-2018-18876 | — | — | 2.4% | Jun 18, 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it po... |
| CVE-2018-18875 | — | — | 0.9% | Jun 18, 2019 | In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allow... |
| CVE-2018-18852 | — | — | 63.8% | Jun 18, 2019 | Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in... |
| CVE-2018-18944 | — | — | 2.7% | Jun 18, 2019 | Artha ~ The Open Thesaurus 1.0.3.0 has a Buffer Overflow. |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now