2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-11760 | — | — | 0.6% | Feb 4, 2019 | When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the us... |
| CVE-2018-19004 | — | — | 3.7% | Feb 1, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, w... |
| CVE-2018-16493 | — | — | 1.8% | Feb 1, 2019 | A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to ... |
| CVE-2018-16492 | — | — | 3.0% | Feb 1, 2019 | A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitra... |
| CVE-2018-16491 | — | — | 1.7% | Feb 1, 2019 | A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary... |
| CVE-2018-16490 | — | — | 1.1% | Feb 1, 2019 | A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary propert... |
| CVE-2018-16486 | — | — | 1.5% | Feb 1, 2019 | A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject prope... |
| CVE-2018-16485 | — | — | 1.3% | Feb 1, 2019 | Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file ... |
| CVE-2018-16484 | — | — | 0.6% | Feb 1, 2019 | A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, du... |
| CVE-2018-16483 | — | — | 1.2% | Feb 1, 2019 | A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the appl... |
| CVE-2018-16481 | — | — | 0.7% | Feb 1, 2019 | A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's br... |
| CVE-2018-16480 | — | — | 0.8% | Feb 1, 2019 | A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due t... |
| CVE-2018-16479 | — | — | 1.7% | Feb 1, 2019 | Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appe... |
| CVE-2018-0722 | — | — | 1.7% | Feb 1, 2019 | Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, ... |
| CVE-2018-18988 | — | — | 2.6% | Feb 1, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report form... |
| CVE-2018-5498 | — | — | 1.2% | Feb 1, 2019 | Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attac... |
| CVE-2018-15779 | — | — | — | Feb 1, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-17928 | — | — | 0.8% | Jan 31, 2019 | The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration f... |
| CVE-2018-6241 | — | — | 0.2% | Jan 31, 2019 | NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the regi... |
| CVE-2018-12548 | — | — | 1.1% | Jan 31, 2019 | In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public ... |
| CVE-2018-19043 | — | — | 10.0% | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)... |
| CVE-2018-19042 | — | — | 10.0% | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di... |
| CVE-2018-19041 | — | — | 2.6% | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the... |
| CVE-2018-19040 | — | — | 12.1% | Jan 31, 2019 | The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para... |
| CVE-2018-18941 | — | — | 2.3% | Jan 31, 2019 | In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discoverin... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now