2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0618 | — | — | 2.0% | Jul 26, 2018 | Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitra... |
| CVE-2018-0617 | — | — | 2.2% | Jul 26, 2018 | Directory traversal vulnerability in ChamaNet MemoCGI v2.1800 to v2.2200 allows remote attackers to read arbitrary files... |
| CVE-2018-0614 | — | — | 0.8% | Jul 26, 2018 | Cross-site scripting vulnerability in NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, C... |
| CVE-2018-0613 | — | — | 1.1% | Jul 26, 2018 | NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D)... |
| CVE-2018-0607 | — | — | 1.2% | Jul 26, 2018 | SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authentic... |
| CVE-2018-14493 | — | — | 40.4% | Jul 25, 2018 | Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inj... |
| CVE-2018-14430 | — | — | 1.3% | Jul 25, 2018 | The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_d... |
| CVE-2018-14083 | — | — | 2.5% | Jul 25, 2018 | LICA miniCMTS E8K(u/i/...) devices allow remote attackers to obtain sensitive information via a direct POST request for ... |
| CVE-2018-13988 | — | — | 3.1% | Jul 25, 2018 | Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped i... |
| CVE-2018-1002209 | — | — | 5.9% | Jul 25, 2018 | QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot ... |
| CVE-2018-1002207 | — | — | 2.5% | Jul 25, 2018 | mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allo... |
| CVE-2018-1002206 | — | — | 10.1% | Jul 25, 2018 | SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a .... |
| CVE-2018-1002203 | — | — | 11.9% | Jul 25, 2018 | unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files ... |
| CVE-2018-1002202 | — | — | 13.1% | Jul 25, 2018 | zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot d... |
| CVE-2018-1002200 | — | — | 13.2% | Jul 25, 2018 | plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ... |
| CVE-2018-5240 | — | — | 1.1% | Jul 25, 2018 | The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to... |
| CVE-2018-5542 | — | — | 1.2% | Jul 25, 2018 | F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the m... |
| CVE-2018-5541 | — | — | 1.8% | Jul 25, 2018 | When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing HTTP requests, an u... |
| CVE-2018-5539 | — | — | 1.8% | Jul 25, 2018 | Under certain conditions, on F5 BIG-IP ASM 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, 11.5.1-11.5.6, or 11.2.1, ... |
| CVE-2018-5538 | — | — | 0.8% | Jul 25, 2018 | On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management inte... |
| CVE-2018-5537 | — | — | 1.2% | Jul 25, 2018 | A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.... |
| CVE-2018-5536 | — | — | 2.4% | Jul 25, 2018 | A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 v... |
| CVE-2018-5531 | — | — | 0.5% | Jul 25, 2018 | Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent ... |
| CVE-2018-5530 | — | — | 1.8% | Jul 25, 2018 | F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerab... |
| CVE-2018-6971 | — | — | 0.4% | Jul 25, 2018 | VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure log... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now