2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-7649 | — | — | 0.6% | Aug 2, 2018 | Monitorix before 3.10.1 allows XSS via CGI variables. |
| CVE-2018-8037 | — | — | 12.1% | Aug 2, 2018 | If an async request was completed by the application at the same time as the container triggered the async timeout, a ra... |
| CVE-2018-1329 | — | — | — | Aug 2, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2018-12448 | — | — | 0.8% | Aug 2, 2018 | Whale Browser before 1.3.48.4 displays no URL information but only a title of a web page on the browser's address bar wh... |
| CVE-2018-3109 | — | — | 2.0% | Aug 2, 2018 | Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder... |
| CVE-2018-3108 | — | — | 1.8% | Aug 2, 2018 | Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification S... |
| CVE-2018-2933 | — | — | 1.0% | Aug 2, 2018 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S... |
| CVE-2018-14840 | — | — | 3.7% | Aug 2, 2018 | uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam... |
| CVE-2018-14838 | — | — | 0.7% | Aug 2, 2018 | rejucms 2.1 has stored XSS via the admin/book.php content parameter. |
| CVE-2018-14836 | — | — | 1.0% | Aug 2, 2018 | Subrion 4.2.1 is vulnerable to Improper Access control because user groups not having access to the Admin panel are able... |
| CVE-2018-14835 | — | — | 0.7% | Aug 2, 2018 | Subrion CMS v4.2.1 is vulnerable to Stored XSS because of no escaping added to the tooltip information being displayed i... |
| CVE-2018-10624 | — | — | 0.8% | Aug 1, 2018 | In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerabilit... |
| CVE-2018-0413 | — | — | 1.2% | Aug 1, 2018 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2018-0411 | — | — | 1.8% | Aug 1, 2018 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthentic... |
| CVE-2018-0408 | — | — | 0.7% | Aug 1, 2018 | A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could ... |
| CVE-2018-0407 | — | — | 0.7% | Aug 1, 2018 | A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could ... |
| CVE-2018-0406 | — | — | 1.8% | Aug 1, 2018 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticat... |
| CVE-2018-0397 | — | — | 1.5% | Aug 1, 2018 | A vulnerability in Cisco AMP for Endpoints Mac Connector Software installed on Apple macOS 10.12 could allow an unauthen... |
| CVE-2018-0391 | — | — | 2.7% | Aug 1, 2018 | A vulnerability in the password change function of Cisco Prime Collaboration Provisioning could allow an authenticated, ... |
| CVE-2018-14777 | — | — | 0.7% | Aug 1, 2018 | An issue was discovered in DataLife Engine (DLE) through 13.0. An attacker can use XSS (related to the /addnews.html and... |
| CVE-2018-10618 | — | — | 10.1% | Aug 1, 2018 | Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke... |
| CVE-2018-3672 | — | — | 0.4% | Aug 1, 2018 | Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute... |
| CVE-2018-3671 | — | — | 0.4% | Aug 1, 2018 | Escalation of privilege in Intel Saffron admin application before 11.4 allows an authenticated user to access unauthoriz... |
| CVE-2018-3670 | — | — | 0.4% | Aug 1, 2018 | Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute... |
| CVE-2018-3666 | — | — | 0.4% | Aug 1, 2018 | Driver module in Intel Smart Sound Technology before version 9.21.00.3541 potentially allows a local attacker to execute... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now