2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-1744 | HIGH | 7.7 | 2.6% | Oct 15, 2018 | IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the s... |
| CVE-2018-18324 | — | — | 3.2% | Oct 15, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter... |
| CVE-2018-18323 | — | — | 70.7% | Oct 15, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/... |
| CVE-2018-18322 | — | — | 15.1% | Oct 15, 2018 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/ind... |
| CVE-2018-18320 | — | — | 5.2% | Oct 15, 2018 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary ... |
| CVE-2018-18319 | — | — | 5.4% | Oct 15, 2018 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary ... |
| CVE-2018-18318 | — | — | 1.2% | Oct 15, 2018 | The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a de... |
| CVE-2018-18317 | — | — | 0.5% | Oct 15, 2018 | DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI. |
| CVE-2018-18316 | — | — | 0.5% | Oct 15, 2018 | emlog v6.0.0 has CSRF via the admin/user.php?action=new URI. |
| CVE-2018-18315 | — | — | 1.2% | Oct 15, 2018 | com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFil... |
| CVE-2018-18310 | MEDIUM | 5.5 | 1.5% | Oct 15, 2018 | An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.1... |
| CVE-2018-18309 | — | — | 1.8% | Oct 15, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. A... |
| CVE-2018-18296 | — | — | 0.7% | Oct 15, 2018 | MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action. |
| CVE-2018-18291 | — | — | 0.8% | Oct 14, 2018 | A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject a... |
| CVE-2018-18290 | — | — | 0.6% | Oct 14, 2018 | An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HT... |
| CVE-2018-18289 | — | — | 1.1% | Oct 14, 2018 | The MESILAT Zabbix plugin before 1.1.15 for Atlassian Confluence allows attackers to read arbitrary files. |
| CVE-2018-18287 | — | — | 1.7% | Oct 14, 2018 | On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLease... |
| CVE-2018-18282 | — | — | 1.0% | Oct 12, 2018 | Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page. |
| CVE-2018-10141 | — | — | 3.9% | Oct 12, 2018 | GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject a... |
| CVE-2018-18274 | — | — | 1.2% | Oct 12, 2018 | A issue was found in pdfalto 0.2. There is a heap-based buffer overflow in the TextPage::addAttributsNode function in Xm... |
| CVE-2018-16210 | MEDIUM | 6.1 | 1.0% | Oct 12, 2018 | WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP config... |
| CVE-2018-15755 | MEDIUM | 6.6 | 1.3% | Oct 12, 2018 | Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL... |
| CVE-2018-14664 | MEDIUM | 5.4 | 1.1% | Oct 12, 2018 | A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly ... |
| CVE-2018-18271 | — | — | 0.8% | Oct 12, 2018 | XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News--... |
| CVE-2018-18270 | — | — | 0.8% | Oct 12, 2018 | XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->New... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now