2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2018-1273CRITICAL9.8Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property...
CVE-2018-9852CRITICAL9.8In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by...
CVE-2018-1270CRITICAL9.8Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow app...
CVE-2018-9309CRITICAL9.8An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.
CVE-2018-9284CRITICAL9.8authentication.cgi on D-Link DIR-868L devices with Singapore StarHub firmware before v1.21SHCb03 allows remote attackers...
CVE-2018-1469CRITICAL9.8IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system comma...
CVE-2018-3822CRITICAL9.8X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonic...
CVE-2018-4841CRITICAL9.8A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port...
CVE-2018-7600CRITICAL9.8Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi...
CVE-2018-0171CRITICAL9.8A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica...
CVE-2018-0151CRITICAL9.8A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an...
CVE-2018-0150CRITICAL9.8A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running a...
CVE-2018-9110CRITICAL9.1Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function...
CVE-2018-9109CRITICAL9.1Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function...
CVE-2018-9032CRITICAL9.8An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Versi...
CVE-2018-1312CRITICAL9.8In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent repl...
CVE-2018-8967CRITICAL9.8An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
CVE-2018-1000141CRITICAL9.1I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can r...
CVE-2018-1000138CRITICAL9.1I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php tha...
CVE-2018-7520CRITICAL9.8An improper access control vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline T...
CVE-2018-8088CRITICAL9.8org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass int...
CVE-2018-7445CRITICAL9.8A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remot...
CVE-2018-5551CRITICAL9Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain thr...
CVE-2018-1000124CRITICAL10I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of import...
CVE-2018-7750CRITICAL9.8transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now