2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-7649Monitorix before 3.10.1 allows XSS via CGI variables.
CVE-2018-8037If an async request was completed by the application at the same time as the container triggered the async timeout, a ra...
CVE-2018-1329Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2018-12448Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar wh...
CVE-2018-3109Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder...
CVE-2018-3108Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification S...
CVE-2018-2933Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S...
CVE-2018-14840uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam...
CVE-2018-14838rejucms 2.1 has stored XSS via the admin/book.php content parameter.
CVE-2018-14836Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able...
CVE-2018-14835Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed i...
CVE-2018-10624In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerabilit...
CVE-2018-0413A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2018-0411A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthentic...
CVE-2018-0408A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could ...
CVE-2018-0407A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could ...
CVE-2018-0406A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticat...
CVE-2018-0397A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthen...
CVE-2018-0391A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, ...
CVE-2018-14777An issue was discovered in DataLife Engine (DLE) through 13.0. An attacker can use XSS (related to the /addnews.html and...
CVE-2018-10618Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke...
CVE-2018-3672Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute...
CVE-2018-3671Escalation of privilege in Intel Saffron admin application before 11.4 allows an authenticated user to access unauthoriz...
CVE-2018-3670Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute...
CVE-2018-3666Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now