2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-0384 | — | — | 2.5% | Jul 16, 2018 | A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attack... |
| CVE-2018-0383 | — | — | 3.0% | Jul 16, 2018 | A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attack... |
| CVE-2018-0370 | — | — | 2.2% | Jul 16, 2018 | A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attack... |
| CVE-2018-0369 | — | — | 2.3% | Jul 16, 2018 | A vulnerability in the reassembly logic for fragmented IPv4 packets of Cisco StarOS running on virtual platforms could a... |
| CVE-2018-0368 | — | — | 0.3% | Jul 16, 2018 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to acces... |
| CVE-2018-0366 | — | — | 1.8% | Jul 16, 2018 | A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticat... |
| CVE-2018-0361 | — | — | 1.6% | Jul 16, 2018 | ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively smal... |
| CVE-2018-0360 | — | — | 1.7% | Jul 16, 2018 | ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor fil... |
| CVE-2018-0341 | — | — | 5.9% | Jul 16, 2018 | A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.... |
| CVE-2018-13981 | — | — | 17.3% | Jul 16, 2018 | The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code ... |
| CVE-2018-11717 | — | — | 8.6% | Jul 16, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a contex... |
| CVE-2018-11716 | — | — | 14.3% | Jul 16, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to al... |
| CVE-2018-5229 | — | — | 0.6% | Jul 16, 2018 | The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remot... |
| CVE-2018-14071 | — | — | 3.1% | Jul 16, 2018 | The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input. |
| CVE-2018-13387 | — | — | 1.5% | Jul 16, 2018 | The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5,... |
| CVE-2018-14089 | — | — | 0.9% | Jul 16, 2018 | An issue was discovered in a smart contract implementation for Virgo_ZodiacToken, an Ethereum token. In this contract, '... |
| CVE-2018-14088 | — | — | 1.3% | Jul 16, 2018 | An issue was discovered in a smart contract implementation for STeX White List (STE(WL)), an Ethereum token. The contrac... |
| CVE-2018-14085 | — | — | 0.9% | Jul 16, 2018 | An issue was discovered in a smart contract implementation for UserWallet 0x0a7bca9FB7AfF26c6ED8029BB6f0F5D291587c42, an... |
| CVE-2018-14073 | — | — | 1.5% | Jul 15, 2018 | libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c. |
| CVE-2018-14072 | — | — | 1.4% | Jul 15, 2018 | libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buffer_resize in fromsixel.c, and sixel_dec... |
| CVE-2018-14069 | — | — | 0.5% | Jul 15, 2018 | An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin... |
| CVE-2018-14068 | — | — | 0.7% | Jul 15, 2018 | An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Adm... |
| CVE-2018-14066 | — | — | 0.4% | Jul 15, 2018 | The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phone... |
| CVE-2018-14065 | — | — | 2.2% | Jul 15, 2018 | XMLReader.php in PHPOffice Common before 0.2.9 allows XXE. |
| CVE-2018-14064 | — | — | 37.6% | Jul 15, 2018 | The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now